Skip to content

MCPA-2026-0068

lowrce-vectorsCVSS 5.3

mcp-pdf-vision page-extraction command injection (CVE-2026-19279)

mcp-pdf-vision (npm) 1.1.0: the load_pdf/extract_page path in src/index.ts interpolates the pdfPath and sessionId arguments into a pdftoppm shell command executed via child_process exec, allowing command injection through crafted paths or session ids (a double quote in pdfPath escapes the quoting). Version 1.0.0 does not contain the exec-based extraction. The project was informed through a public issue but has not responded and no fixed release exists, so the range is recorded as last_affected 1.1.0 per the public advisory.

Affected packages

EcosystemPackageAffected versions
npmmcp-pdf-vision
>= 1.1.0, <= 1.1.0

Identifiers

CVE-2026-19279GHSA-jgc6-5vgc-hvqgCWE-74

References

Timeline

  • Published: 2026-08-08

← All advisories