Cyber & AI intelligence
Wasteland.
Briefs indexed3091
Issues31
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-107699 2026-10-08

CVE-2026-107699: Critical OS Command Injection in ppt2png npm Package

"ppt2png through version 0.0.6 contains a critical OS command injection flaw (CVSS 3.1 9.8). If an application passes attacker-controlled file paths to the library, an attacker who includes shell metacharacters in those…"

ppt2png through version 0.0.6 contains a critical OS command injection flaw (CVSS 3.1 9.8). If an application passes attacker-controlled file paths to the library, an attacker who includes shell metacharacters in those paths can run arbitrary operating system commands.

What Is It

CVE-2026-107699 is an OS command injection vulnerability (CWE-78) in ppt2png, an npm package maintained by tzwm. The NVD description says the package does not sanitize its input and output path arguments. It passes those file names to child_process.exec() in ppt2png.js. An attacker who puts shell metacharacters such as ; in a file name can run commands with the privileges of the Node.js process.

VulnCheck disclosed the issue, and NVD published it on 2026-10-08. The NVD record is currently in Deferred status.

Why It Matters

VulnCheck rates the flaw CRITICAL under both CVSS versions:

Under the CVSS 3.1 vector, an attacker can reach the flaw over the network with low complexity. No privileges or user interaction are needed. The impact on confidentiality, integrity and availability is high. A successful exploit lets the attacker run commands at the same privilege level as the Node.js process that calls the library.

CISA KEV does not list this CVE. No KEV entry was supplied, so active exploitation is not confirmed. A public gist linked from the NVD record documents the issue.

What's Vulnerable

Field Value
Vendor tzwm
Product ppt2png
Ecosystem npm (pkg:npm/ppt2png)
Affected versions 0 through 0.0.6 (inclusive)
Vulnerable code child_process.exec() call in ppt2png.js

The vendor's default status is "unaffected." The listed range is the only one marked as affected.

Patch Status

The supplied NVD and KEV data do not name a fixed version or an official patch. NVD lists every version up to and including 0.0.6 as affected. Because there is no KEV entry, CISA has not set a required action or due date.

Users of ppt2png should:

Sources