CVE-2018-3746: Pdfinfojs Project Pdfinfojs

Critical severity, CVSS 9.8. EPSS: 4.9% chance of exploitation in the next 30 days.

The pdfinfojs NPM module versions <= 0.3.6 has a command injection vulnerability that allows an attacker to execute arbitrary commands on the victim's machine.

Affected products

Published 2018-06-01. Last modified 2026-06-17.