External risk intelligence

enmaso node-convert OS command injection via unsanitized arguments

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-107703

This is a library used within Node.js applications. While it processes input that could be reached via a web application, it is not an internet-facing service, appliance, or gateway itself. Its exposure is entirely dependent on whether the developer integrates it into a public-facing endpoint, which is plausible but not a standard or inherent deployment pattern for this specific component.

OS Command Injection

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory addresses a vulnerability in a Node.js library that could allow attackers to execute commands on the server if the library is used in a way that processes unsanitized user input. The primary concern is to confirm if this library is in use and if it is exposed to external input.

  • Unsanitized input can execute server commands.
  • Understand if this library is part of our systems.
  • Confirm if it's exposed to external input.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending specially crafted input, likely through a web application that uses the affected library. This input, containing malicious shell metacharacters, is passed to a function that executes system commands without proper sanitization. Successful exploitation allows an attacker to run arbitrary operating system commands with the privileges of the Node.js process.

  • Entry condition: Network access to an application using the library.
  • Trigger point: Unsanitized filepath and convertTo arguments.
  • Resulting risk: Arbitrary OS command execution.

Live Threat

Current exploitation, exposure, and threat context

The `@enmaso/node-convert` library, when used with versions up to 1.0.0, allows for the execution of arbitrary operating system commands. This is possible because unsanitized input in the `filepath` and `convertTo` arguments can be used to inject malicious commands into the ImageMagick process. When this vulnerability is exploited, an attacker could potentially execute commands with the same privileges as the Node.js process.

  • System data and behavior.
  • Via unsanitized input to arguments.
  • Arbitrary command execution.

Operational Fix

Recommended remediation, mitigation, and detection steps

The `@enmaso/node-convert` library's OS command injection vulnerability in `convert.js` impacts Node.js applications. Owners of applications that utilize this library, particularly those processing user-supplied file paths or conversion targets, are responsible for assessing and mitigating risk. The first practical step is to identify all instances of the affected library, determine their reachability and business criticality, and then plan remediation.

  • Application owners should manage this issue.
  • Verify library usage and exposure paths.
  • Plan coordinated remediation and testing.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the @enmaso/node-convert library?

This is a Node.js library used by developers to handle file conversions, often relying on ImageMagick tools in the background. It simplifies tasks like changing image formats by bridging Node.js code with system-level processing utilities.

What does OS command injection mean for CVE-2026-107703?

This is a CWE-78 weakness where the library fails to clean user-provided data before passing it to the system. Because the input is treated as part of an executable command string, an attacker can insert special characters to force the server to run unintended, malicious shell commands.

How can an attacker trigger this vulnerability?

An attacker must supply specially crafted values for the 'filepath' or 'convertTo' arguments within the library. Simply having the library installed is not enough; the bug only triggers if the application code passes untrusted, unsanitized user input directly into these specific library functions.

Do I need to worry if my application is not internet-facing?

Halo Surface Signal notes that since this is a library, your risk depends on how it is integrated into your software. If an application using this library accepts input from the internet, it faces higher risk. If the usage is purely internal or restricted to authenticated, trusted users, the potential for external exploitation is reduced.

What are the first steps to address this vulnerability?

Start by auditing your codebase to locate where @enmaso/node-convert is used. Once identified, evaluate if those specific functions process user-supplied file paths or conversion types. If so, prioritize these areas for updates or architectural changes to ensure input is strictly validated before use.

References