← Back to CVE List
CVE-2016-10320
textract before 1.5.0 allows OS Command Injection attacks via a filename in a call to the process function. This may be a remote attack if a web application accepts names of arbitrary uploaded files.
> MITRE Terms of Use apply – see LICENSE‑MITRE.txt