ppt2png through version 0.0.6 contains a critical OS command injection flaw (CVSS 3.1 9.8). If an application passes attacker-controlled file paths to the library, an attacker who includes shell metacharacters in those paths can run arbitrary operating system commands.
What Is It
CVE-2026-107699 is an OS command injection vulnerability (CWE-78) in ppt2png, an npm package maintained by tzwm. The NVD description says the package does not sanitize its input and output path arguments. It passes those file names to child_process.exec() in ppt2png.js. An attacker who puts shell metacharacters such as ; in a file name can run commands with the privileges of the Node.js process.
VulnCheck disclosed the issue, and NVD published it on 2026-10-08. The NVD record is currently in Deferred status.
Why It Matters
VulnCheck rates the flaw CRITICAL under both CVSS versions:
- CVSS 3.1: 9.8 (
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) - CVSS 4.0: 9.3. The available data gives the exploitability metrics (network attack vector, low complexity, no attack requirements, no privileges, no user interaction) and high impact on the vulnerable system's confidentiality, integrity and availability. It does not give the subsequent-system impact metrics (SC/SI/SA), so the full 4.0 base vector is not reproduced here.
Under the CVSS 3.1 vector, an attacker can reach the flaw over the network with low complexity. No privileges or user interaction are needed. The impact on confidentiality, integrity and availability is high. A successful exploit lets the attacker run commands at the same privilege level as the Node.js process that calls the library.
CISA KEV does not list this CVE. No KEV entry was supplied, so active exploitation is not confirmed. A public gist linked from the NVD record documents the issue.
What's Vulnerable
| Field | Value |
|---|---|
| Vendor | tzwm |
| Product | ppt2png |
| Ecosystem | npm (pkg:npm/ppt2png) |
| Affected versions | 0 through 0.0.6 (inclusive) |
| Vulnerable code | child_process.exec() call in ppt2png.js |
The vendor's default status is "unaffected." The listed range is the only one marked as affected.
Patch Status
The supplied NVD and KEV data do not name a fixed version or an official patch. NVD lists every version up to and including 0.0.6 as affected. Because there is no KEV entry, CISA has not set a required action or due date.
Users of ppt2png should:
- Find every place the package appears in their dependencies.
- Check the project repository and the VulnCheck advisory for remediation updates.
- Treat any setup that passes untrusted file paths to the library as exposed until a fix is confirmed.