vendor:
pdfkit
by:
UNICORD (NicPWNs & Dev-Yeoj)
7.5
CVSS
HIGH
Command Injection
78
CWE
Product Name: pdfkit
Affected Version From: 0.0.0
Affected Version To: 0.8.7.2
Patch Exists: YES
Related CWE: CVE-2022–25765
CPE: a:pdfkit:pdfkit:0.8.7.2
Platforms Tested: pdfkit 0.8.6
2023
pdfkit v0.8.7.2 – Command Injection
The package pdfkit from 0.0.0 are vulnerable to Command Injection where the URL is not properly sanitized.
Mitigation:
Sanitize the URL before passing it to the pdfkit package.