pdf2html is vulnerable to Path Traversal
72
High Risk
Affected versions of this package are vulnerable to path traversal due to insufficient validation of the filepath parameter in the generateImage function. An attacker could manipulate filepath to escape the intended directory by using relative paths, allowing arbitrary file read/write operations when processing PDFs or generating images, potentially leading to unauthorized access or system compromise.
You are affected if you are using a version that falls within the vulnerable range.
pdf2html is vulnerable to Path Traversal in versions 4.1.0 - 4.3.0.
Upgrade the pdf2html library to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant