CVE-2016-10320: Textract Project Textract
High severity, CVSS 7.8. EPSS: 2.1% chance of exploitation in the next 30 days.
textract before 1.5.0 allows OS Command Injection attacks via a filename in a call to the process function. This may be a remote attack if a web application accepts names of arbitrary uploaded files.
Affected products
- Textract Project Textract: up to and including 1.4.0
Published 2017-04-06. Last modified 2026-06-17.