ocrmypdf is vulnerable to Code Injection
64
Medium Risk
OCRmyPDF ships a misc/watcher.py helper that runs OCRmyPDF on files dropped into configurable input, output, and archive directories. When those processing folders overlap the installation's interpreter paths, virtual environment, plugins, or settings file and are writable by the users who submit files, a submitter can plant code or point the settings at a malicious plugin that the helper then loads and executes. This grants code execution with the privileges of the account running the watcher. The fix adds startup validation that refuses to run when data directories overlap code or writable settings, and stops the helper from following symlinks or processing non-regular files.
You are affected if you are using a version that falls within the vulnerable range and you deploy the misc/watcher.py helper with processing folders that overlap the installation's code, plugins, or configuration and are writable by the users who submit files.
ocrmypdf is vulnerable to Code Injection in versions 0.0.1 - 17.8.1.
Upgrade the ocrmypdf library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant