What is CVE-2026-16770?
CVE-2026-16770 is an argument injection vulnerability in Perl's PDF::WebKit library up to version 1.2, exploitable via <meta> tags in the source HTML document passed to wkhtmltopdf. This can lead to remote code execution. Users must update the library and sanitize any user-supplied HTML input immediately.
Azərbaycanca: CVE-2026-16770, Perl üçün PDF::WebKit kitabxanasının 1.2-yə qədər olan versiyalarında, mənbə sənəddəki <meta> teqləri vasitəsilə wkhtmltopdf əmrinə arqument injection həyata keçirməyə imkan verən boşluqdur. Bu, uzaqdan kod icrasına səbəb ola bilər. İstifadəçilər dərhal kitabxananı yeniləməli və daxil edilən HTML məzmununu ciddi şəkildə filtrləməlidir.
Related CVEs
link basis: same weakness class CWE-77
FAQ2
Which library is affected by CVE-2026-16770, and what are the version limitations?
This vulnerability affects Perl's PDF::WebKit library up to version 1.2.
How can an attacker achieve remote code execution by exploiting CVE-2026-16770?
An attacker can achieve remote code execution by injecting arguments into the wkhtmltopdf command via <meta> tags in the source HTML document.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.