A 'critical' 9.8 bug just landed on an npm package nobody's updated since 2014
CVE-2026-107699 scores the maximum on the danger scale, but the small print matters: the tool is obscure, abandoned, and only a problem if you're doing something risky with it anyway.
A newly catalogued security flaw, CVE-2026-107699, has been handed the maximum possible severity rating a vulnerability can get: 9.8 out of 10 on the CVSS scale. That sounds like the kind of thing that should have IT departments scrambling. In this case, it’s worth taking a breath before anyone does.
What the bug actually does
The flaw sits in ppt2png, a small Node.js package on GitHub that converts PowerPoint files to PNG images by shelling out to two other tools, unoconv and ImageMagick’s convert. According to the researcher who found it, writing under the handle Retro16 in a public write-up, the package builds its command-line instructions by simply gluing filenames straight into a string, with no escaping or sanitisation whatsoever.
That means if you can control the filename or output path that gets fed to ppt2png, you can smuggle in your own commands. The gist’s proof of concept passes a filename like /x; touch /tmp/pwned; echo done and watches the extra command execute on the system - no need for the conversion tool itself to even be installed. In plain terms: an attacker who can influence those two inputs can potentially run arbitrary commands on the server, which is about as bad as a bug gets.
So who is actually at risk
This is the part that matters more than the headline score. ppt2png is a niche, largely forgotten npm package with 23 stars and six forks - hardly infrastructure the internet runs on. Its GitHub repository shows no meaningful activity since it was first written over a decade ago, and the researcher’s own notes confirm the project has been dormant since 2014.
The flaw is also “context-dependent,” as the researcher themselves put it. It isn’t exploitable just by the package existing on a server - a developer’s own application has to be passing untrusted, user-supplied text into the conversion function’s input or output arguments. That’s a specific and avoidable coding mistake, not a flaw that silently exposes every installation by default. A 9.8 CVSS score reflects the worst-case technical impact if that condition is met, not how many real systems are actually exposed right now.
We have no evidence from the available sources that this bug is being actively exploited in the wild, and no figures on how many live deployments still rely on this package. Given its age and obscurity, that number is likely to be small.
What to do about it
Because the project has had no real maintenance in years, there’s no official patch to install. If your own code uses ppt2png, or you’ve inherited a project that does, the fix suggested by the researcher is straightforward: stop using Node’s exec() with concatenated strings and switch to execFile() or spawn() with arguments passed as a proper array, which strips out the ability to inject shell commands entirely. Better still, given the package’s inactivity, this is a good moment to replace it with something actively maintained.
For everyone else - which is to say, the overwhelming majority of readers who have never heard of ppt2png and never will - this isn’t a bug that touches your laptop, your phone, or any mainstream software. It’s a reminder that “critical” severity scores describe technical worst-case potential, not real-world reach, and that the two numbers are worth checking separately before anyone starts worrying.