Impact
An OS command injection flaw (CWE‑78) exists in the app.py module of the openlabs docker‑wkhtmltopdf‑aas container. By sending a crafted POST request, an attacker can cause the service to execute arbitrary shell commands on the host machine, allowing full compromise of confidentiality, integrity, and availability.
Affected Systems
The vulnerability affects any deployment of the openlabs docker‑wkhtmltopdf‑aas image that includes app.py from a commit prior to 9f50579. No other vendors or unrelated products are listed, so the scope is limited to this Docker image and its variants.
Risk and Exploitability
The CVSS score is 9.8, indicating critical severity. The EPSS score of 1% shows a very low but nonzero probability of exploitation, yet the impact is severe enough to warrant urgent remediation. This issue is not listed in the CISA KEV catalog. Attackers only need the ability to reach the exposed HTTP endpoint and can trigger command execution with a single crafted POST request, underscoring the high exploitation risk.
OpenCVE Enrichment