What is CVE-2026-16766?
Catalyst::View::Wkhtmltopdf versions before 0.6.1 contain a shell command injection flaw leading to remote code execution (RCE) when user-controlled PDF render options are passed unsanitized to the wkhtmltopdf command. Applications using affected versions must upgrade to 0.6.1 and enforce strict input sanitization immediately.
Azərbaycanca: Catalyst::View::Wkhtmltopdf-in 0.6.1-dən əvvəlki versiyalarında shell command injection boşluğu mövcuddur ki, bu da uzaqdan kod icrasına (RCE) səbəb ola bilər. Təsirə məruz qalan tətbiqlər istifadəçi tərəfindən idarə olunan render seçimlərini təmizləmədən birbaşa wkhtmltopdf əmrinə ötürür. İstifadəçilər dərhal 0.6.1 versiyasına yeniləməli və istifadəçi girişlərinin ciddi filtrasiyasını təmin etməlidirlər.
Related CVEs
link basis: same weakness class CWE-77
FAQ2
Which software component is affected by CVE-2026-16766?
This vulnerability affects versions of Catalyst::View::Wkhtmltopdf before 0.6.1.
How can one protect against CVE-2026-16766?
Affected applications must upgrade to version 0.6.1 and enforce strict input sanitization for user-controlled render options.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.