<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cve-2026-107699 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/cve-2026-107699/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 08 Oct 2026 19:39:29 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/cve-2026-107699/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>OS Command Injection in ppt2png Library</title><link>https://feed.craftedsignal.io/briefs/2026-10-ppt2png-rce/</link><pubDate>Thu, 08 Oct 2026 19:39:29 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-ppt2png-rce/</guid><description>The ppt2png npm package (version 0.0.6 and earlier) is vulnerable to OS command injection via unsanitized file path arguments passed to child_process.exec(), enabling arbitrary code execution.</description><content:encoded><![CDATA[<p>The ppt2png npm package version 0.0.6 and earlier contains a critical OS command injection vulnerability, identified as CVE-2026-107699. The vulnerability stems from improper sanitization of user-supplied input and output path arguments within the ppt2png.js module. Specifically, the library uses the Node.js <code>child_process.exec()</code> function to execute system commands, but it fails to escape or sanitize shell metacharacters provided in filename parameters. An attacker can exploit this by injecting characters like the semicolon (<code>;</code>) into an argument, allowing them to terminate the intended command and append malicious OS commands. These commands execute with the same privileges as the Node.js application process. This vulnerability presents a high risk to any application using the library to process user-provided file paths, potentially leading to full system compromise depending on the process context.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for arbitrary code execution on the server hosting the application. This could result in unauthorized data access, exfiltration of sensitive information, or the deployment of persistent malware within the infrastructure of organizations utilizing the vulnerable package in their software supply chain.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Identify all applications utilizing the ppt2png npm package version 0.0.6 or earlier and update to a remediated version if available.</li>
<li>If no patched version exists, implement input validation to sanitize all filenames and file path arguments, rejecting any strings containing shell metacharacters such as <code>;</code>, <code>|</code>, <code>&amp;</code>, <code>$</code>, or <code>&gt;</code>.</li>
<li>Run the Node.js application process with the least privilege possible to minimize the impact of potential command execution.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>supply-chain</category><category>command-injection</category><category>nodejs</category><category>cve-2026-107699</category></item></channel></rss>