mooz / node-pdf-image

Provides an interface to convert PDF's pages to png files in Node.js by using ImageMagick
MIT License
237 stars 87 forks source link

Security issue #38

Open lirantal opened 6 years ago

lirantal commented 6 years ago

Hi,

I'm a member of the Node.js Security WG and we received a report regarding a security issue with this module. We tried inviting the author by e-mail but received no response so I'm opening this issue and inviting anyone with commit and npm publish rights to collaborate with us on a fix.

roest01 commented 6 years ago

Hello @lirantal, you can contact me because of this issue via [anonymized]

May i can fix and provide an PR

lirantal commented 6 years ago

Yes @roest01, please check your inbox for the invite

queval-j commented 5 years ago

Any news about this issue?

roest01 commented 5 years ago

PR is made. Issue is fixed there ...

roest01 commented 5 years ago

Maybe someone or some could do a code review of #39 to help @mooz merging this ?

svrnwnsch commented 5 years ago

As long as there is no new version how can I sanitize input for the current 2.0.0 version?