


Perceptive Security
SOC/SIEM Consultancy

An OS command injection vulnerability in the app.py component of openlabs docker-wkhtmltopdf-aas up to commit 9f50579 allows attackers to execute arbitrary comm…
Published:
2 June 2026 at 22:00:00
Alert date:
3 June 2026 at 20:02:27
Source:
nvd.nist.gov
Web Technologies, Cloud & Virtualization, Supply Chain & Dependencies
A critical OS command injection vulnerability exists in the app.py component of openlabs docker-wkhtmltopdf-aas up to commit 9f50579. The vulnerability allows remote attackers to execute arbitrary operating system commands through specially crafted POST requests. This affects the Docker-based HTML to PDF conversion service, potentially allowing full system compromise. The vulnerability is accessible via the application's web interface and could lead to complete server takeover. Organizations using this Docker image should immediately update or implement mitigations.
Technical details
Mitigation steps:
Affected products:
openlabs docker-wkhtmltopdf-aas
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-36576
https://github.com/openlabs/docker-wkhtmltopdf-aas
https://github.com/openlabs/docker-wkhtmltopdf-aas/blob/9f505797671c3339520dec5fc01dff3a6f324f2e/app.py#L40
https://github.com/openlabs/docker-wkhtmltopdf-aas/issues/36
https://hub.docker.com/r/openlabs/docker-wkhtmltopdf-aas
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
