漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
node-tesseract-ocr is an npm package that provides a Node.js wrapper for Tesseract OCR. In all versions through 2.2.1, the recognize() function in src/index.js is vulnerable to OS Command Injection. The file path parameter is concatenated into a shell command string and passed to child_process.exec() without proper sanitization
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
N/A
Vulnerability Title
Tesseract 安全漏洞
Vulnerability Description
Tesseract是Nazim Gafarov个人开发者的一个Node.js平台的OCR图像文字识别库。 Tesseract 2.2.1及之前版本存在安全漏洞,该漏洞源于文件路径参数未经验证,可能导致OS命令注入攻击。
CVSS Information
N/A
Vulnerability Type
N/A