GHSA-mvhf-547c-h55r

Suggest an improvement
Source
https://github.com/advisories/GHSA-mvhf-547c-h55r
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-mvhf-547c-h55r/GHSA-mvhf-547c-h55r.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-mvhf-547c-h55r
Aliases
  • CVE-2026-26833
Published
2026-03-25T18:31:47Z
Modified
2026-03-31T23:41:22Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
thumbler allows OS Command Injection
Details

thumbler through 1.1.2 allows OS command injection via the input, output, time, or size parameter in the thumbnail() function because user input is concatenated into a shell command string passed to child_process.exec() without proper sanitization or escaping.

Database specific
{
    "cwe_ids":  [
        "CWE-78",
        "CWE-94"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-03-31T23:24:12Z",
    "nvd_published_at":  "2026-03-25T16:16:21Z",
    "severity":  "CRITICAL"
}
References

Affected packages

npm / thumbler

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
1.1.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-mvhf-547c-h55r/GHSA-mvhf-547c-h55r.json"