A vulnerability was identified in Fdawgs node-poppler versions up to 9.1.2 and 10.0.1 affecting multiple PDF processing functions in src/index.js. The flaw resides in the Argument Injection Handler component, where manipulation of the file_path argument leads to argument injection. Affected functions include pdfInfo, pdfToText, pdfToCairo, pdfToPpm, pdfImages, pdfToHtml, pdfToPs, pdfFonts, pdfDetach, pdfAttach, pdfSeparate, and pdfUnite. The vulnerability can be exploited remotely, increasing its risk surface. A patch has been identified with commit hash db6e3f79d3beb20601be7e59669c39811ae3c330 on the project's GitHub repository. Users are strongly advised to apply the patch immediately to mitigate the risk of exploitation.