CVE-2026-16770: PDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via meta tags in the source document
PDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via meta tags in the source document.
For an HTML string or file source, the constructor collects every <meta name="pdf-webkit-KEY" content="VALUE"> element in the document head through pdfwebkitmetatags and turns each one into a wkhtmltopdf command line option. KEY is normalized to an option name matching --[a-z0-9-]+ but is not checked against an allow list, VALUE is passed through unchanged as the argument that follows it, and a VALUE of "yes" emits the option as a bare flag. BUILD merges the meta derived options last, so they also override the module defaults and the options passed to new. Switches such as --enable-local-file-access and --cookie-jar are reachable this way. The renderer is executed with an argument list rather than a shell command, so this is argument injection and not shell injection.
Any caller that renders untrusted HTML lets the document choose the renderer's options and override those set by the application, including options that read local files into the resulting PDF or write to a chosen path. A URL source is not scanned, and the scan is skipped when XML::LibXML, a recommended dependency, is not installed.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
PDF::WebKit (Perl)to a version that resolves this vulnerability.Fixed in 1.2Patch CVE-2026-16770 - Configuration
Do not allow untrusted HTML to supply wkhtmltopdf command-line options via <meta name="pdf-webkit-KEY" content="VALUE"> in the document head (PDF::WebKit uses _pdf_webkit_meta_tags to convert them into wkhtmltopdf options).
PDF::WebKit meta tag options (pdf-webkit-KEY content=VALUE) = Disable processing of <meta name="pdf-webkit-KEY" ...> from untrusted HTML sources - Configuration
Implement/enable validation so normalized pdf-webkit KEY values matching --[a-z0-9-]+ are checked against an allow list instead of being accepted without validation; do not pass VALUE unchanged into wkhtmltopdf arguments.
PDF::WebKit allow list for pdf-webkit-KEY = Enforce allow list (deny by default) - Compensating control
If wkhtmltopdf is invoked with options like --enable-local-file-access or --cookie-jar, ensure these options cannot be triggered by untrusted input (e.g., block/strip pdf-webkit meta tags that would cause these switches to be reachable).
- Operational
Audit and re-render any PDFs generated from untrusted HTML that may have contained malicious pdf-webkit meta tags, since injected options could cause reading local files or writing to a chosen path.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16770?
CVE-2026-16770 has a risk score of 65, indicating a medium severity vulnerability.
How do I fix CVE-2026-16770?
To fix CVE-2026-16770, upgrade to the latest version of PDF::WebKit that addresses this vulnerability.
What software is affected by CVE-2026-16770?
CVE-2026-16770 affects PDF::WebKit versions through 1.2 for Perl.
What type of vulnerability is CVE-2026-16770?
CVE-2026-16770 is an argument injection vulnerability that allows manipulation via meta tags.
What impact does CVE-2026-16770 have on applications?
CVE-2026-16770 can lead to unintended command execution within the wkhtmltopdf tool when processing HTML documents.