CVE-2018-3746
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 4.9%
exploitation probability
4.9%top 8% of all CVEs
observed exploitation
nono source reports it
The pdfinfojs NPM module versions <= 0.3.6 has a command injection vulnerability that allows an attacker to execute arbitrary commands on the victim's machine.
Affected products
HackerOne · pdfinfojsReferences
https://hackerone.com/reports/330957