SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-78637

HIGH · CVSS 7.3 EPSS 0.33% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-25 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

A high-severity vulnerability exists in the Fdawgs node-poppler library versions up to 9.1.2/10.0.1, specifically within the argument injection handler functions in src/index.js. This flaw allows remote attackers to manipulate the `file_path` argument, potentially leading to unauthorized access or execution of arbitrary code. Organizations using affected versions should prioritize applying the patch (db6e3f79d3beb20601be7e59669c39811ae3c330) to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-78637
Severity
HIGH
CVSS
7.3
EPSS
0.33%

Original NVD Description

A vulnerability was detected in Fdawgs node-poppler up to 9.1.2/10.0.1. The impacted element is the function pdfInfo/pdfToText/pdfToCairo/pdfToPpm/pdfImages/pdfToHtml/pdfToPs/pdfFonts/pdfDetach/pdfAttach/pdfSeparate/pdfUnite of the file src/index.js of the component Argument Injection Handler. Performing a manipulation of the argument file_path results in argument injection. The attack may be initiated remotely. The patch is named db6e3f79d3beb20601be7e59669c39811ae3c330. It is recommended to apply a patch to fix this issue.