RubySec

Providing security resources for the Ruby community

CVE-2022-25765 (pdfkit): PDFKit vulnerable to Command Injection

PDFKit vulnerable to Command Injection

Published: September 10, 2022

SECURITY IDENTIFIERS

GEM

pdfkit

SEVERITY

CVSS v3.x: 9.8 (Critical)

PATCHED VERSIONS

>= 0.8.7.2

DESCRIPTION

The package pdfkit from version 0.0.0 through version 0.8.6 is vulnerable to Command Injection where the URL is not properly sanitized.

RELATED