Skip to content
Vulnerabilities

Organisations Risk Remote Code Execution via Critical Command Injection in @enmaso/node-convert Library

A critical command injection flaw in @enmaso/node-convert allows remote execution of system commands through unsanitized inputs.

Organisations Risk Remote Code Execution via Critical Command Injection in @enmaso/node-convert Library
Illustration: Malware Brief

Key points

  • CVE-2026-107703 is rated 9.3 CVSS critical
  • The vulnerability exists in versions up to 1.0.0
  • Attackers exploit unsanitized filepath arguments

Security researchers have identified a severe vulnerability in a popular Node.js library used for image processing. The flaw, tracked as CVE-2026-107703, permits attackers to execute arbitrary operating system commands on servers running the affected software. This issue poses a significant risk to organisations relying on this library for handling user-uploaded images or automated conversion tasks.

How it unfolded

  • The vulnerability was documented in the National Vulnerability Database as CVE-2026-107703.
  • Analysts determined the issue stems from improper input sanitisation in the convert.js file.
  • It was found that attackers could inject shell metacharacters or single quotes into the filepath and convertTo arguments.
  • These inputs are passed directly to ImageMagick via child_process.exec(), allowing command execution with the privileges of the Node.js process.

Who is affected

Organisations using the @enmaso/node-convert library are exposed to this risk. Specifically, any installation running version 1.0.0 or earlier is vulnerable. The flaw is classified under CWE-78 (Improper Neutralisation of Special Elements used in an OS Command). Because the library facilitates image conversion, it is commonly found in web applications that allow users to upload or process media files. If an attacker can control the file path or conversion parameters passed to this library, they can manipulate the underlying ImageMagick command. This enables them to run system commands on the host server, potentially leading to full system compromise depending on the permissions granted to the Node.js process.

The fix

The National Vulnerability Database record specifies that the vulnerability affects the library through version 1.0.0. However, the source material does not confirm the release of a patched version or a specific update that resolves this issue. Until a vendor-provided fix is available, systems running the affected versions remain at risk. Administrators should monitor official channels for updates regarding a secure version of the library.

What to do and how to stay safe: CVE-2026-107703

  • Audit your Node.js project dependencies to determine if @enmaso/node-convert is in use.
  • Review application code for any instances where user-controlled inputs are passed to image conversion functions.
  • Implement strict input validation to reject unexpected characters in file paths and conversion arguments.
  • Monitor server logs for unusual command execution patterns or unexpected process spawns.

Step-by-step guide: Patch Management: Eight Questions Answered for Stability

General security guidance from the Malware Brief newsroom. It is not confirmed advice from the organisations named in this story.

Frequently asked questions

What is the severity of CVE-2026-107703?

The National Vulnerability Database rates the vulnerability as 9.3 CVSS, which is classified as critical.

Which versions of the library are affected?

The flaw affects @enmaso/node-convert versions up to and including 1.0.0.

How do attackers exploit this vulnerability?

Attackers inject shell metacharacters or single quotes into the filepath and convertTo arguments, which are then executed by ImageMagick via child_process.exec().

Sources

  1. CVE Program
  2. NVD
CVE-2026-107703@enmaso/node-convertNode.jsImageMagickOS command injection

Related stories

Skyeye TTS Vulnerability Enables Unauth PowerShell Execution on Windows Servers

A critical unauthenticated command injection in Dromara Skyeye allows remote attackers to execute PowerShell code on Windows servers via a text-to-speech endpoint.

Cybersecurity news without the noiseDaily Briefing