Impact
Vulnerability in Catalyst::View::Wkhtmltopdf occurs when application parameters are concatenated into the wkhtmltopdf command line without sanitization, creating a shell command injection flaw (CWE-78). An attacker who can control options such as page_size, orientation or margins can inject arbitrary shell commands, resulting in remote code execution. The flaw exists in all releases before version 0.6.1, including the incomplete fix in 0.6.0.
Affected Systems
Perl applications using the Catalyst::View::Wkhtmltopdf module before version 0.6.1. Specifically, RRWO Catalyst::View::Wkhtmltopdf 0.6.0 and earlier are affected.
Risk and Exploitability
The EPSS score is below 1%, indicating a low predicted exploitation frequency, but the vulnerability offers unrestricted command execution on the server and is listed outside the CISA KEV catalog. Exploitation requires a web application that forwards user‑controlled wkhtmltopdf options; the attack vector is inferred to be remote via the application’s input interface.
OpenCVE Enrichment