CVE-2026-26831 — textract through 2.5.0 is vulnerable to OS Command Injection via the file path parameter in multiple extractors. When processing files with malicious filenames, the filePath is passed directly to chil — CVE Database · The Intelligence Room