GITHUBEXPLOIT 9.8 CRITICAL

Exploit for CVE-2022-25765_1B97A135-40DA-5D6A-A356-05F36B943967

9.8 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

Command Injection quando processa URLs não sanitizadas. Isso acontece porque o pdfkit passa a URL diretamente para o binário wkhtmltopdf sem sanitização adequada, e wkhtmltopdf pode interpretar partes da URL como comandos do shell se houver caracteres...
Visit Original Source

Basic Information

ID 1B97A135-40DA-5D6A-A356-05F36B943967
Published Dec 11, 2025 at 23:13
Modified Dec 11, 2025 at 23:15

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.