← back
CVE-2026-26832

CVE-2026-26832

CVSS 9.8 CRITICALEPSS 1.7%CWE-78
Vexday Risk Score
28Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 9.8EPSS 1.7%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
25 Mar 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
node-tesseract-ocr is an npm package that provides a Node.js wrapper for Tesseract OCR. In all versions through 2.2.1, the recognize() function in src/index.js is vulnerable to OS Command Injection. The file path parameter is concatenated into a shell command string and passed to child_process.exec() without proper sanitization
CVSS:3.1/AC:L/AV:N/A:H/C:H/I:H/PR:N/S:U/UI:N
Affected products
n/a · n/a