VYPR

PDF::WebKit

by Perl Foundation

CVEs (1)

  • CVE-2026-17431Aug 13, 2026
    risk 0.00cvss epss

    PDF::WebKit versions through 1.2 for Perl allow OS command injection via a 2-arg open() of the output path in to_pdf and of stylesheet paths in _style_tag_for. to_pdf reads the generated PDF back from its path argument, and _style_tag_for reads each entry of the stylesheets…