CPANSA-Catalyst-View-Wkhtmltopdf-2026-16766: Catalyst-View-Wkhtmltopdf vulnerability
| Publisher | giterlizzi | Document category | csaf_security_advisory |
|---|---|---|---|
| Initial release date | 2026-07-25T00:00:00 | Engine | CSAF Perl Toolkit 0.26 |
| Current release date | 2026-07-25T00:00:00 | Build Date | |
| Current version | 1 | Status | final |
| CVSS v3.1 Base Score | 9.8 | Severity | Critical |
| Original language | Language | en | |
| Also referred to | |||
Vulnerability Description
Catalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell command injection (RCE) via PDF render options.
Options are passed directly to the wkhtmltopdf command without sanitization.
Any web application that passes user-controlled options such as the page_size, orientation or margins without validation allows shell command injection.
Version 0.6.0 was released with an incomplete fix for this issue.
Note that the wkhtmltopdf project is no longer being developed, and users of this package should migrate to alternative solutions.
Vulnerabilities
CVE-2026-16766
Vulnerability DescriptionCatalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell command injection (RCE) via PDF render options.
Options are passed directly to the wkhtmltopdf command without sanitization.
Any web application that passes user-controlled options such as the page_size, orientation or margins without validation allows shell command injection.
Version 0.6.0 was released with an incomplete fix for this issue.
Note that the wkhtmltopdf project is no longer being developed, and users of this package should migrate to alternative solutions.
| Weakness | CWE-78 : Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') |
|---|
Product status
Known affected
| Product | Score | ||||||||
|---|---|---|---|---|---|---|---|---|---|
| Catalyst-View-Wkhtmltopdf less than 0.6.1 |
|
Fixed
- Catalyst-View-Wkhtmltopdf greater than or equal 0.6.1
giterlizzi
Namespace: https://github.com/giterlizzi/
gdt@cpan.org
References
- CPANSA-Catalyst-View-Wkhtmltopdf-2026-16766 JSON self
https://raw.githubusercontent.com/giterlizzi/perl-CPANSA-CSAF/develop/csaf/white/2026/cpansa-catalyst-view-wkhtmltopdf-2026-16766.json - https://github.com/mc7244/Catalyst-View-Wkhtmltopdf/issues/6 external
https://github.com/mc7244/Catalyst-View-Wkhtmltopdf/issues/6 - https://github.com/robrwo/Catalyst-View-Wkhtmltopdf/security/advisories/GHSA-42w4-jj8w-6p98 external
https://github.com/robrwo/Catalyst-View-Wkhtmltopdf/security/advisories/GHSA-42w4-jj8w-6p98 - https://metacpan.org/release/RRWO/Catalyst-View-Wkhtmltopdf-v0.6.1/changes external
https://metacpan.org/release/RRWO/Catalyst-View-Wkhtmltopdf-v0.6.1/changes - http://www.openwall.com/lists/oss-security/2026/07/25/4 external
http://www.openwall.com/lists/oss-security/2026/07/25/4 - CVE-2026-16766 (NVD) external
https://nvd.nist.gov/vuln/detail/CVE-2026-16766
Revision history
| Version | Date of the revision | Summary of the revision |
|---|---|---|
| 1 | Sat Jul 25 00:00:00 2026 | First release |
Sharing rules
TLP:WHITE
For the TLP version see: https://www.first.org/tlp/