PT-2026-64476 · Cpan · Catalyst::View::Wkhtmltopdf
CVE-2026-16766
·
Published
2026-07-25
·
Updated
2026-08-13
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Catalyst::View::Wkhtmltopdf versions prior to 0.6.1
Description
Shell command injection is possible via PDF render options because options are passed directly to the wkhtmltopdf command without sanitization. Web applications that pass user-controlled variables such as
page size, orientation, or margins without validation are susceptible to remote code execution (RCE).Recommendations
Update Catalyst::View::Wkhtmltopdf to version 0.6.1 or later.
As a temporary mitigation, avoid passing user-controlled input to the
page size, orientation, and margins options.Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Catalyst::View::Wkhtmltopdf