Command injection exists in pdf-image v2.0.0 due to an unescaped string parameter.Referenceshttps://hackerone.com/reports/340208https://github.com/roest01/node-pdf-image/commit/54679496a89738443917608c2bbe2f6e5dd20e83