CVE-2014-3741: Node-Printer Project Node-Printer

Critical severity, CVSS 9.8. EPSS: 3.8% chance of exploitation in the next 30 days.

The printDirect function in lib/printer.js in the node-printer module 0.0.1 and earlier for Node.js allows remote attackers to execute arbitrary commands via unspecified characters in the lpr command.

Affected products

Published 2017-10-23. Last modified 2026-06-17.