CVE-2026-26831 | textract up to 2.5.0 child_process.exec filepath os command injection (EUVD-2026-15459)
A vulnerability categorized as critical has been discovered in textract up to 2.5.0. This impacts the function child_process.exec in the library lib/extractors/doc.js of the file child_process.exec. Such manipulation of the argument filepath leads to os command injection.
This vulnerability is documented as CVE-2026-26831. The attack requires being on the local network. There is not any exploit available.