{"resultsPerPage":8,"startIndex":0,"totalResults":8,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-17T15:55:27.948","vulnerabilities":[{"cve":{"id":"CVE-2018-14865","sourceIdentifier":"cve@mitre.org","published":"2019-07-03T19:15:10.767","lastModified":"2026-06-17T01:41:47.183","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Report engine in Odoo Community 9.0 through 11.0 and earlier and Odoo Enterprise 9.0 through 11.0 and earlier does not use secure options when passing documents to wkhtmltopdf, which allows remote attackers to read local files."},{"lang":"es","value":"El motor de informes en Odoo Community versión 9.0 hasta la versión 11.0 y versiones anteriores y Odoo Enterprise versión 9.0 hasta la versión 11.0 y versiones anteriores no usa opciones seguras al pasar documentos a wkhtmltopdf, lo que permite a los atacantes remotos leer archivos locales."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-200"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:odoo:odoo:9.0:*:*:*:community:*:*:*","matchCriteriaId":"C3F9E8F1-FAF7-44AE-8D05-BE717D247EDE"},{"vulnerable":true,"criteria":"cpe:2.3:a:odoo:odoo:9.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"167C709E-C8B2-4CCB-963E-E1D8C664190A"},{"vulnerable":true,"criteria":"cpe:2.3:a:odoo:odoo:10.0:*:*:*:community:*:*:*","matchCriteriaId":"C52F2EEB-11E5-49E8-AD06-3014FF2C2D24"},{"vulnerable":true,"criteria":"cpe:2.3:a:odoo:odoo:10.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"A4405E54-6C16-49D5-B632-3D72091B2FEB"},{"vulnerable":true,"criteria":"cpe:2.3:a:odoo:odoo:11.0:*:*:*:community:*:*:*","matchCriteriaId":"38424B03-4121-4A79-8E4E-4CB4DCD3E4A5"},{"vulnerable":true,"criteria":"cpe:2.3:a:odoo:odoo:11.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"1298CF62-A06E-48AD-8141-0541DE3F6381"}]}]}],"references":[{"url":"https://github.com/odoo/odoo/issues/32501","source":"cve@mitre.org","tags":["Patch","Third Party Advisory"]},{"url":"https://github.com/odoo/odoo/issues/32501","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2020-10390","sourceIdentifier":"cve@mitre.org","published":"2020-03-12T14:15:13.173","lastModified":"2026-06-17T02:47:41.573","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"OS Command Injection in export.php (vulnerable function called from include/functions-article.php) in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to achieve Code Execution by saving the code to be executed as the wkhtmltopdf path via admin/save-settings.php."},{"lang":"es","value":"Una inyección de comandos de Sistema Operativo en el archivo export.php (función vulnerable llamada desde el archivo include/functions-article.php) en Chadha PHPKB Standard Multi-Language versión 9, permite a atacantes remotos lograr una Ejecución de Código al guardar el código que será ejecutado como la ruta wkhtmltopdf por medio del archivo admin/save-settings.php."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-78"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:chadhaajay:phpkb:9.0:*:*:*:*:*:*:*","matchCriteriaId":"4D001F05-7BFC-43D7-8382-8960A9238E5E"}]}]}],"references":[{"url":"http://antoniocannito.it/?p=137#rce3","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory"]},{"url":"https://antoniocannito.it/phpkb1#out-of-band-blind-authenticated-remote-code-execution-cve-2020-10390","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory"]},{"url":"http://antoniocannito.it/?p=137#rce3","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]},{"url":"https://antoniocannito.it/phpkb1#out-of-band-blind-authenticated-remote-code-execution-cve-2020-10390","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2020-21365","sourceIdentifier":"cve@mitre.org","published":"2022-08-15T20:15:08.107","lastModified":"2026-06-17T03:03:39.013","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Directory traversal vulnerability in wkhtmltopdf through 0.12.5 allows remote attackers to read local files and disclose sensitive information via a crafted html file running with the default configurations."},{"lang":"es","value":"Una vulnerabilidad de salto de directorio en wkhtmltopdf versiones hasta 0.12.5, permite a atacantes remotos leer archivos locales y divulgar información confidencial por medio de un archivo html diseñado que es ejecutado con las configuraciones predeterminadas."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-22"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:wkhtmltopdf:wkhtmltopdf:*:*:*:*:*:*:*:*","versionEndIncluding":"0.12.5","matchCriteriaId":"188C03DB-7001-45E0-BCF9-C31881353BCC"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*","matchCriteriaId":"07B237A9-69A3-4A9C-9DA0-4E06BD37AE73"}]}]}],"references":[{"url":"https://github.com/wkhtmltopdf/wkhtmltopdf/issues/4536","source":"cve@mitre.org","tags":["Exploit","Issue Tracking","Third Party Advisory"]},{"url":"https://lists.debian.org/debian-lts-announce/2022/10/msg00027.html","source":"cve@mitre.org","tags":["Mailing List","Third Party Advisory"]},{"url":"https://github.com/wkhtmltopdf/wkhtmltopdf/issues/4536","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Third Party Advisory"]},{"url":"https://lists.debian.org/debian-lts-announce/2022/10/msg00027.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2022-35583","sourceIdentifier":"cve@mitre.org","published":"2022-08-22T16:15:09.473","lastModified":"2026-06-17T04:51:57.670","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"wkhtmlTOpdf 0.12.6 is vulnerable to SSRF which allows an attacker to get initial access into the target's system by injecting iframe tag with initial asset IP address on it's source. This allows the attacker to takeover the whole infrastructure by accessing their internal assets."},{"lang":"es","value":"wkhtmlTOpdf versión 0.12.6, es vulnerable a un ataque de tipo SSRF que permite a un atacante conseguir acceso inicial en el sistema del objetivo al inyectar una etiqueta iframe con la dirección IP del activo inicial en su origen. Esto permite al atacante tomar el control de toda la infraestructura accediendo a sus activos internos."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:wkhtmltopdf:wkhtmltopdf:0.12.6:*:*:*:*:*:*:*","matchCriteriaId":"68FDACEB-29B7-4F6A-9645-7F84E5B8653D"}]}]}],"references":[{"url":"http://packetstormsecurity.com/files/171446/wkhtmltopdf-0.12.6-Server-Side-Request-Forgery.html","source":"cve@mitre.org","tags":["Exploit"]},{"url":"https://cyber-guy.gitbook.io/cyber-guys-blog/blogs/initial-access-via-pdf-file-silently","source":"cve@mitre.org","tags":["URL Repurposed"]},{"url":"https://drive.google.com/file/d/1LAmf_6CJLk5qDp0an2s_gVQ0TN2wmht5/view?usp=sharing","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory"]},{"url":"https://wkhtmltopdf.org/","source":"cve@mitre.org","tags":["Product","Vendor Advisory"]},{"url":"http://packetstormsecurity.com/files/171446/wkhtmltopdf-0.12.6-Server-Side-Request-Forgery.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"]},{"url":"https://cyber-guy.gitbook.io/cyber-guys-blog/blogs/initial-access-via-pdf-file-silently","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["URL Repurposed"]},{"url":"https://drive.google.com/file/d/1LAmf_6CJLk5qDp0an2s_gVQ0TN2wmht5/view?usp=sharing","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]},{"url":"https://wkhtmltopdf.org/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Product","Vendor Advisory"]}]}},{"cve":{"id":"CVE-2024-13285","sourceIdentifier":"mlhess@drupal.org","published":"2025-01-09T20:15:37.470","lastModified":"2026-06-17T07:01:41.177","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Vulnerability in Drupal wkhtmltopdf.This issue affects wkhtmltopdf: *.*."},{"lang":"es","value":"Vulnerabilidad en Drupal wkhtmltopdf. Este problema afecta a wkhtmltopdf: *.*."}],"affected":[{"source":"mlhess@drupal.org","affectedData":[{"vendor":"Drupal","product":"wkhtmltopdf","defaultStatus":"unaffected","collectionURL":"https://www.drupal.org/project/wkhtmltopdf","repo":"https://git.drupalcode.org/project/wkhtmltopdf","versions":[{"version":"*.*","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-01-10T16:14:27.755053Z","id":"CVE-2024-13285","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:wkhtmltopdf:wkhtmltopdf:*:*:*:*:*:drupal:*:*","matchCriteriaId":"DF942FDD-D0C4-4288-8150-9CB04CD26628"}]}]}],"references":[{"url":"https://www.drupal.org/sa-contrib-2024-049","source":"mlhess@drupal.org","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2025-51591","sourceIdentifier":"cve@mitre.org","published":"2025-07-11T14:15:27.347","lastModified":"2026-07-05T17:17:15.480","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"A Server-Side Request Forgery (SSRF) in JGM Pandoc v3.6.4 allows attackers to gain access to and compromise the whole infrastructure via injecting a crafted iframe. Note: Some users have stated that Pandoc by default can retrieve and parse untrusted HTML content which can enable SSRF vulnerabilities. Using the ‘--sandbox’ option or ‘pandoc-server’ can mitigate such vulnerabilities. Using pandoc with an external ‘--pdf-engine’ can also enable SSRF vulnerabilities, such as CVE-2022-35583 in wkhtmltopdf."},{"lang":"es","value":"Server-Side Request Forgery (SSRF) en JGM Pandoc v3.6.4 permite a los atacantes obtener acceso y comprometer toda la infraestructura mediante la inyección de un iframe manipulado específicamente."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":3.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-10-07T15:56:45.462102Z","id":"CVE-2025-51591","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-918"}]}],"references":[{"url":"https://github.com/RealestName/Vulnerability-Research/tree/main/CVE-2025-51591","source":"cve@mitre.org"},{"url":"https://github.com/jgm/pandoc/discussions/11200","source":"cve@mitre.org"},{"url":"https://github.com/jgm/pandoc/issues/10682","source":"cve@mitre.org"},{"url":"https://github.com/jgm/pandoc/issues/11261","source":"cve@mitre.org"},{"url":"https://github.com/jgm/pandoc/issues/8874","source":"cve@mitre.org"},{"url":"https://github.com/jgm/pandoc/pull/11262","source":"cve@mitre.org"},{"url":"https://www.wiz.io/blog/imds-anomaly-hunting-zero-day","source":"cve@mitre.org"},{"url":"https://github.com/jgm/pandoc/commit/67edf7ce7cd3563a180ae44bd122b012e22364f8","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://github.com/jgm/pandoc/issues/10682","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://pandoc.org","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://www.wiz.io/blog/imds-anomaly-hunting-zero-day","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"not-applicable:http://jgm.com/","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"not-applicable:http://pandoc.com/","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}},{"cve":{"id":"CVE-2026-16766","sourceIdentifier":"9b29abf9-4ab0-4765-b253-1875cd9b441e","published":"2026-07-25T09:16:32.000","lastModified":"2026-08-13T00:17:31.593","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Catalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell command injection (RCE) via PDF render options.\n\nOptions are passed directly to the wkhtmltopdf command without sanitization.\n\nAny web application that passes user-controlled options such as the page_size, orientation or margins without validation allows shell command injection.\n\nVersion 0.6.0 was released with an incomplete fix for this issue.\n\nNote that the wkhtmltopdf project is no longer being developed, and users of this package should migrate to alternative solutions."}],"affected":[{"source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","affectedData":[{"vendor":"RRWO","product":"Catalyst::View::Wkhtmltopdf","defaultStatus":"unaffected","collectionURL":"https://cpan.org/modules","packageName":"Catalyst-View-Wkhtmltopdf","programFiles":["lib/Catalyst/View/Wkhtmltopdf.pm"],"programRoutines":[{"name":"Catalyst::View::Wkhtmltopdf::render"}],"repo":"https://github.com/robrwo/Catalyst-View-Wkhtmltopdf","versions":[{"version":"0","lessThan":"0.6.1","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-27T15:57:42.687945Z","id":"CVE-2026-16766","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary","description":[{"lang":"en","value":"CWE-78"}]}],"references":[{"url":"https://github.com/mc7244/Catalyst-View-Wkhtmltopdf/issues/6","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"url":"https://github.com/robrwo/Catalyst-View-Wkhtmltopdf/security/advisories/GHSA-42w4-jj8w-6p98","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"url":"https://metacpan.org/release/RRWO/Catalyst-View-Wkhtmltopdf-v0.6.1/changes","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"url":"https://wkhtmltopdf.org/status.html","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"url":"http://www.openwall.com/lists/oss-security/2026/07/25/4","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-16770","sourceIdentifier":"9b29abf9-4ab0-4765-b253-1875cd9b441e","published":"2026-08-13T00:17:31.763","lastModified":"2026-08-13T13:17:46.820","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"PDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via meta tags in the source document.\n\nFor an HTML string or file source, the constructor collects every <meta name=\"pdf-webkit-KEY\" content=\"VALUE\"> element in the document head through _pdf_webkit_meta_tags and turns each one into a wkhtmltopdf command line option. KEY is normalized to an option name matching --[a-z0-9-]+ but is not checked against an allow list, VALUE is passed through unchanged as the argument that follows it, and a VALUE of \"yes\" emits the option as a bare flag. BUILD merges the meta derived options last, so they also override the module defaults and the options passed to new. Switches such as --enable-local-file-access and --cookie-jar are reachable this way. The renderer is executed with an argument list rather than a shell command, so this is argument injection and not shell injection.\n\nAny caller that renders untrusted HTML lets the document choose the renderer's options and override those set by the application, including options that read local files into the resulting PDF or write to a chosen path. A URL source is not scanned, and the scan is skipped when XML::LibXML, a recommended dependency, is not installed."}],"affected":[{"source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","affectedData":[{"vendor":"MITHALDU","product":"PDF::WebKit","defaultStatus":"unaffected","collectionURL":"https://cpan.org/modules","packageName":"PDF-WebKit","programFiles":["lib/PDF/WebKit.pm"],"programRoutines":[{"name":"PDF::WebKit::BUILD"},{"name":"PDF::WebKit::_find_options_in_meta"},{"name":"PDF::WebKit::_pdf_webkit_meta_tags"}],"repo":"https://github.com/kingpong/perl-PDF-WebKit","versions":[{"version":"0","lessThanOrEqual":"1.2","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-13T13:08:14.277268Z","id":"CVE-2026-16770","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary","description":[{"lang":"en","value":"CWE-88"}]}],"references":[{"url":"https://github.com/kingpong/perl-PDF-WebKit/issues/9","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"url":"https://security.metacpan.org/patches/P/PDF-WebKit/1.2/CVE-2026-16770-r1.patch","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"url":"https://wkhtmltopdf.org/status.html","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/13/2","source":"af854a3a-2127-422b-91ae-364da2661108"}]}}]}