CVE-2022-25765
Command Injection
- Published
- Sep 9, 2022
- Updated
- Sep 16, 2024
- Assigning CNA
- snyk
- Evidence observed
- Aug 7, 2026
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HModerate · next 30 days
- Percentile
- 98.7%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
The package pdfkit from 0.0.0 are vulnerable to Command Injection where the URL is not properly sanitized.
Sources
10Python proof-of-concept for CVE-2022-25765, a command injection vulnerability in pdfkit, enabling remote code execution via crafted PDF generation.
- CVE-2022-25765-exploitExploit
Python exploit for CVE-2022-25765 command injection in pdfkit, enabling remote code execution via crafted URLs with reverse shell and custom command modes.
- CVE-2022-25765Exploit
Python PoC exploit for CVE-2022-25765, a critical command injection in PDFKit. Generates a reverse shell via unsanitized URL parameters passed to wkhtmltopdf. Includes usage instructions and technical vulnerability analysis.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.