CRITICAL
tzwm
CVE published 2026-10-08
CVE-2026-107699
CVE-2026-107699 is a critical OS command injection vulnerability in ppt2png through version 0.0.6. Attackers can execute operating system commands by supplying unsanitized input or output path arguments, utilizing shell metacharacters like ';' in file names passed to child_process.exec() in ppt2png.js, running commands with Node.js process privileges.