Argument Injection Vulnerability in PDF::WebKit for Perl
CVE-2026-16770
Currently unrated
What is CVE-2026-16770?
The PDF::WebKit module for Perl versions up to 1.2 vulnerability allows argument injection through meta tags in the source HTML document. This occurs when the module collects tags and converts them into command line options without validating the option names against an allow list. As a result, malicious users can manipulate rendering options, potentially enabling local file access or altering the renderer's behavior. Applications rendering untrusted HTML may face risks as these meta-derived options can override application-set configurations, leading to unauthorized data exposure or file manipulation.
Affected Version(s)
PDF::WebKit 0 <= 1.2
