The package ntesseract before 0.2.9 is vulnerable to Command Injection via lib/tesseract.js. References https://nvd.nist.gov/vuln/detail/CVE-2020-28446 https://github.com/taoyuan/ntesseract/commit/fcbc36f381798b4362179c0cdf9961b437c7b619 https://security.snyk.io/vuln/SNYK-JS-NTESSERACT-1050982 https://github.com/advisories/GHSA-w868-4576-rv24