Vendor
The zerox library version 1.1.20 is susceptible to OS command injection via maliciously crafted URLs that interpolate unsanitized file extensions into shell-executed poppler utility commands.