{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/node-poppler/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-78637"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["node-poppler"],"_cs_severities":["high"],"_cs_tags":["supply-chain","vulnerability","argument-injection"],"_cs_type":"advisory","_cs_vendors":["Fdawgs"],"content_html":"\u003cp\u003eCVE-2026-78637 is an argument injection vulnerability affecting Fdawgs node-poppler versions up to 9.1.2 and 10.0.1. The flaw exists within the Argument Injection Handler logic located in src/index.js, impacting multiple functions including pdfInfo, pdfToText, pdfToCairo, pdfToPpm, pdfImages, pdfToHtml, pdfToPs, pdfFonts, pdfDetach, pdfAttach, pdfSeparate, and pdfUnite. By manipulating the file_path argument provided to these functions, a remote attacker can influence the underlying system command execution. This vulnerability is critical for applications that pass user-supplied file paths to these node-poppler methods, as it enables the execution of arbitrary command-line flags. Defenders should prioritize updating to the patched version, as identified by commit hash db6e3f79d3beb20601be7e59669c39811ae3c330.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for argument injection, which may result in unauthorized command execution or the modification of standard command behavior. This affects any application utilizing node-poppler to process user-provided file paths.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the node-poppler dependency to a version containing the patch referenced in commit db6e3f79d3beb20601be7e59669c39811ae3c330.\u003c/li\u003e\n\u003cli\u003eAudit applications utilizing node-poppler to ensure that all inputs passed to file_path parameters are strictly validated against a whitelist of expected formats before being processed.\u003c/li\u003e\n\u003cli\u003eApply the patch for CVE-2026-78637 across all affected environments immediately.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-25T06:05:47Z","date_published":"2026-08-25T06:05:47Z","id":"https://feed.craftedsignal.io/briefs/2026-08-node-poppler-argument-injection/","summary":"An argument injection vulnerability in the node-poppler package allows remote attackers to inject malicious command-line arguments via the file_path parameter.","title":"CVE-2026-78637 Argument Injection in Fdawgs node-poppler","url":"https://feed.craftedsignal.io/briefs/2026-08-node-poppler-argument-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Node-Poppler","version":"https://jsonfeed.org/version/1.1"}