Published: October 8, 2026 | Last Modified: October 8, 2026
ppt2png through 0.0.6 contains an OS command injection vulnerability that allows attackers to execute operating system commands by supplying unsanitized input or output path arguments. Attackers can append shell metacharacters such as ';' to file names passed to child_process.exec() in ppt2png.js, running commands with Node.js process privileges.
Exploitation Probability (EPSS): Moderate — 1.47% (73th percentile)
Measurable exploitation probability. Should be patched in the normal vulnerability management cycle.
This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.