zerox version 1.1.20 contains a critical OS command injection vulnerability in its file download mechanism. The vulnerability arises because temporary file extensions derived from document URLs are interpolated unsanitized into shell commands executed by poppler utilities. Attackers can craft malicious document URLs with file extensions containing command substitution syntax to execute arbitrary OS commands. The exploitation occurs before document processing begins, making it an early-stage attack vector. The vulnerable code resides in the node-zerox package's file utility module. This affects users of the zerox AI-powered document processing library. Successful exploitation could lead to full system compromise on affected hosts.