PatchSiren

enmaso CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL enmaso CVE published 2026-10-08

CVE-2026-107703

CVE-2026-107703 is a critical OS command injection vulnerability in the @enmaso/node-convert package. Attackers can inject shell metacharacters or a single quote into the ImageMagick command to execute operating system commands with Node.js process privileges. This CVE was published on 2026-10-08T18:36:36.868Z and last modified on 2026-10-08T19:18:07.571Z.