{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-107699/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:ppt2png_project:ppt2png:*:*:*:*:*:node.js:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-107699"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["ppt2png (\u003c= 0.0.6)"],"_cs_severities":["critical"],"_cs_tags":["supply-chain","command-injection","nodejs","cve-2026-107699"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe ppt2png npm package version 0.0.6 and earlier contains a critical OS command injection vulnerability, identified as CVE-2026-107699. The vulnerability stems from improper sanitization of user-supplied input and output path arguments within the ppt2png.js module. Specifically, the library uses the Node.js \u003ccode\u003echild_process.exec()\u003c/code\u003e function to execute system commands, but it fails to escape or sanitize shell metacharacters provided in filename parameters. An attacker can exploit this by injecting characters like the semicolon (\u003ccode\u003e;\u003c/code\u003e) into an argument, allowing them to terminate the intended command and append malicious OS commands. These commands execute with the same privileges as the Node.js application process. This vulnerability presents a high risk to any application using the library to process user-provided file paths, potentially leading to full system compromise depending on the process context.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for arbitrary code execution on the server hosting the application. This could result in unauthorized data access, exfiltration of sensitive information, or the deployment of persistent malware within the infrastructure of organizations utilizing the vulnerable package in their software supply chain.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify all applications utilizing the ppt2png npm package version 0.0.6 or earlier and update to a remediated version if available.\u003c/li\u003e\n\u003cli\u003eIf no patched version exists, implement input validation to sanitize all filenames and file path arguments, rejecting any strings containing shell metacharacters such as \u003ccode\u003e;\u003c/code\u003e, \u003ccode\u003e|\u003c/code\u003e, \u003ccode\u003e\u0026amp;\u003c/code\u003e, \u003ccode\u003e$\u003c/code\u003e, or \u003ccode\u003e\u0026gt;\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eRun the Node.js application process with the least privilege possible to minimize the impact of potential command execution.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-08T19:39:29Z","date_published":"2026-10-08T19:39:29Z","id":"https://feed.craftedsignal.io/briefs/2026-10-ppt2png-rce/","summary":"The ppt2png npm package (version 0.0.6 and earlier) is vulnerable to OS command injection via unsanitized file path arguments passed to child_process.exec(), enabling arbitrary code execution.","title":"OS Command Injection in ppt2png Library","url":"https://feed.craftedsignal.io/briefs/2026-10-ppt2png-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-107699","version":"https://jsonfeed.org/version/1.1"}