CVE-2016-10320: Textract Project Textract

High severity, CVSS 7.8. EPSS: 2.1% chance of exploitation in the next 30 days.

textract before 1.5.0 allows OS Command Injection attacks via a filename in a call to the process function. This may be a remote attack if a web application accepts names of arbitrary uploaded files.

Affected products

Published 2017-04-06. Last modified 2026-06-17.