PatchSiren

tzwm CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL tzwm CVE published 2026-10-08

CVE-2026-107699

CVE-2026-107699 is a critical OS command injection vulnerability in ppt2png through version 0.0.6. Attackers can execute operating system commands by supplying unsanitized input or output path arguments, utilizing shell metacharacters like ';' in file names passed to child_process.exec() in ppt2png.js, running commands with Node.js process privileges.