← Back to browse
·
API
CVE-2020-28446
Severity
CRITICAL
CVSS
9.8
EPSS
0.03472
Risk score
40.42
CISA KEV
No
PoC
No
Published
2022-07-25
Modified
2024-09-17
First seen
2026-08-07
Aliases
EUVD-2022-6430, GHSA-W868-4576-RV24
Products
n/a:ntesseract unspecified <0.2.9
Sources
euvd
EUVD-2022-6430
Description
The package ntesseract before 0.2.9 are vulnerable to Command Injection via lib/tesseract.js.
References
https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-6430
https://security.snyk.io/vuln/SNYK-JS-NTESSERACT-1050982
https://github.com/taoyuan/ntesseract/commit/fcbc36f381798b4362179c0cdf9961b437c7b619