CVE-2023-29566
CRITICALDawnsparks-node-tesseract < 0.4.1 - Command Injection
Title source: ruleDescription
huedawn-tesseract 0.3.3 and dawnsparks-node-tesseract 0.4.0 to 0.4.1 was discovered to contain a remote code execution (RCE) vulnerability via the child_process function.
References (4)
Core 4
Scores
CVSS v3
9.8
EPSS
0.0430
EPSS Percentile
88.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
total
Details
CWE
CWE-94
CWE-77
Status
published
Products (4)
dawnsparks-node-tesseract_project/dawnsparks-node-tesseract
0.4.0
dawnsparks-node-tesseract_project/dawnsparks-node-tesseract
0.4.1
huedawn-tesseract_project/huedawn-tesseract
0.3.0
npm/dawnsparks-node-tesseract
0 - 0.4.1npm
Published
Apr 24, 2023
Tracked Since
Feb 18, 2026