top of page
perceptive_background_267k.jpg

An OS command injection vulnerability in the app.py component of openlabs docker-wkhtmltopdf-aas up to commit 9f50579 allows attackers to execute arbitrary comm…

Published:

2 June 2026 at 22:00:00

Alert date:

3 June 2026 at 20:02:27

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Cloud & Virtualization, Supply Chain & Dependencies

A critical OS command injection vulnerability exists in the app.py component of openlabs docker-wkhtmltopdf-aas up to commit 9f50579. The vulnerability allows remote attackers to execute arbitrary operating system commands through specially crafted POST requests. This affects the Docker-based HTML to PDF conversion service, potentially allowing full system compromise. The vulnerability is accessible via the application's web interface and could lead to complete server takeover. Organizations using this Docker image should immediately update or implement mitigations.

Technical details

Mitigation steps:

Affected products:

openlabs docker-wkhtmltopdf-aas

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page