CVE-2026-85672 Details
Description
zerox 1.1.20 contains an OS command injection vulnerability in the file download mechanism where the temporary file extension derived from document URLs is interpolated unsanitized into shell commands executed by poppler utilities. Attackers can craft document URLs with malicious file extensions containing command substitution syntax to execute arbitrary OS commands before document processing occurs.
An OS command injection vulnerability has been identified in Zerox version 1.1.20. The issue arises in the file download process, where the temporary file extension is extracted from document URLs and unsanitized before being used in shell commands executed by Poppler utilities. This flaw allows attackers to craft document URLs with malicious file extensions that include command substitution syntax, enabling the execution of arbitrary OS commands on the host machine before the document is processed.
Zerox should be updated to version 1.1.21 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 4, 2026CISA-ADP
Assessed Sep 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/getomni-ai/zerox/issues/206 | CISA-ADP | ExploitIssue TrackingTechnical AnalysisVendor |
| https://github.com/getomni-ai/zerox | [email protected] | Source CodeVendor |
| https://github.com/getomni-ai/zerox/blob/main/node-zerox/src/utils/file.ts | [email protected] | Source CodeVendor |
| https://github.com/getomni-ai/zerox/issues/206 | [email protected] | ExploitIssue TrackingTechnical AnalysisVendor |
| https://www.vulncheck.com/advisories/zerox-1.1.20-os-command-injection-via-document-url-file-extension | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| getomni-ai zerox | <= 1.1.20 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 8, 2026 | CVE Modified | CISA-ADP |
| Sep 4, 2026 | New CVE Received | [email protected] |
Volerion