CVE-2026-16766
A vulnerability in the Catalyst::View::Wkhtmltopdf Perl module allows attackers to inject malicious commands into the system. This happens because user-provided settings, such as page size or margins, are passed directly to the underlying software without being checked for safety.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Users of the Catalyst::View::Wkhtmltopdf Perl module, specifically versions prior to 0.6.1, especially those using web applications that pass user-controlled options to PDF rendering.
Real-world impact
An attacker could gain full control over the server running the application by executing arbitrary commands, potentially leading to complete system compromise.
Why this severity
This is a critical vulnerability because it can be exploited remotely over the internet without any user interaction or special privileges, allowing for total control over the affected system.
What to do about it
- 01Upgrade Catalyst::View::Wkhtmltopdf to version 0.6.1 or later.
- ›Migrate to alternative solutions, as the wkhtmltopdf project is no longer being developed.
NVD-referenced vendor advisory
Timeline
- Jul 25, 2026 · 7d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 27, 2026 · 5d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
- Jul 28, 2026 · 4d agoAdvisory updatedThe NVD record was last revised.