The package ntesseract before 0.2.9 are vulnerable to Command Injection via lib/tesseract.js.
CWE-77
CVE-2020-28447
This affects all versions of package xopen. The injection point is located in line 14 in index.js in the exported function xopen(filepath)
CVE-2020-28451
This affects the package image-tiler before 2.0.2.
CVE-2020-28453
This affects all versions of package npos-tesseract. The injection point is located in line 55 in lib/ocr.js.
CVE-2020-28422
All versions of package git-archive are vulnerable to Command Injection via the exports function.
CVE-2020-28423
This affects all versions of package monorepo-build.