CVE-2026-16766
Catalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell command injection (RCE) via PDF render options
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Catalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell command injection (RCE) via PDF render options. Options are passed directly to the wkhtmltopdf command without sanitization. Any web application that passes user-controlled options such as the page_size, orientation or margins without validation allows shell command injection. Version 0.6.0 was released with an incomplete fix for this issue. Note that the wkhtmltopdf project is no longer being developed, and users of this package should migrate to alternative solutions.
| CWE | CWE-78 |
| Vendor | rrwo |
| Product | catalyst::view::wkhtmltopdf |
| Published | Jul 25, 2026 |
| Last Updated | Jul 25, 2026 |
Stay Ahead of the Next One
Get instant alerts for rrwo catalyst::view::wkhtmltopdf
Be the first to know when new unknown vulnerabilities affecting rrwo catalyst::view::wkhtmltopdf are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
RRWO / Catalyst::View::Wkhtmltopdf
0 < 0.6.1