CVE-2022-25765: Command Injection
The package pdfkit from 0.0.0 are vulnerable to Command Injection where the URL is not properly sanitized.
Other sources
The package pdfkit is vulnerable to Command Injection where the URL is not properly sanitized.
Note: This issue was patched in 0.8.7.2, but the patch was discovered to be ineffective. The updated patch version is 0.8.7.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-25765?
CVE-2022-25765 is classified as a high-severity vulnerability due to its potential for command injection.
How do I fix CVE-2022-25765?
To fix CVE-2022-25765, update the pdfkit package to version 0.8.7.2 or later.
What kind of attack does CVE-2022-25765 enable?
CVE-2022-25765 enables command injection attacks through unsanitized URL inputs.
Which versions of pdfkit are affected by CVE-2022-25765?
CVE-2022-25765 affects all versions of pdfkit prior to version 0.8.7.2.
Is CVE-2022-25765 patched in all distributions?
The patch for CVE-2022-25765 is primarily available in pdfkit version 0.8.7.2; ensure that your specific distribution uses this version or later.