OS Command Injection in PDF::WebKit for Perl Affects Multiple Versions
CVE-2026-17431

Currently unrated

Key Information:

Vendor

Mithaldu

Vendor
CVE Published:
12 August 2026

What is CVE-2026-17431?

PDF::WebKit versions up to 1.2 for Perl are vulnerable to an OS command injection attack. The vulnerability lies in the improper handling of output paths in the to_pdf and stylesheet paths in _style_tag_for functions. Specifically, untrusted input passed to these functions can lead to command execution under the process's user ID, enabling an attacker to execute arbitrary commands. This occurs when values containing pipes or redirection operators are processed, allowing execution instead of file access. Consequently, attackers can either replace the content of a PDF or manipulate filesystem paths, posing a significant security risk.

Affected Version(s)

PDF::WebKit 0 <= 1.2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.