CVE-2022-25765
HIGHPdfkit < 0.8.7.2 - Command Injection
Title source: ruleDescription
The package pdfkit from 0.0.0 are vulnerable to Command Injection where the URL is not properly sanitized.
Exploits (12)
exploitdb
WORKING POC
VERIFIED
by UNICORD · pythonlocalruby
https://www.exploit-db.com/exploits/51293
nomisec
WORKING POC
20 stars
by PurpleWaveIO · poc
https://github.com/PurpleWaveIO/CVE-2022-25765-pdfkit-Exploit-Reverse-Shell
nomisec
WORKING POC
10 stars
by nikn0laty · poc
https://github.com/nikn0laty/PDFkit-CMD-Injection-CVE-2022-25765
github
WORKING POC
by dugisan3rd · pythonpoc
https://github.com/dugisan3rd/exploit/tree/main/cve-2022-25765
References (7)
Scores
CVSS v3
7.3
EPSS
0.8879
EPSS Percentile
99.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Details
Status
published
Products (5)
fedoraproject/fedora
35
fedoraproject/fedora
36
fedoraproject/fedora
37
pdfkit_project/pdfkit
0.0.0
rubygems/pdfkit
0 - 0.8.7.2RubyGems
Published
Sep 09, 2022
Tracked Since
Feb 18, 2026