---
id: CVE-2026-16766
title: >-
  Catalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell command
  injection (RCE) via PDF render options.


  Options are passed directly to the wkhtmltopdf command without sanitization.


  Any web application that passes user-co…
summary: >-
  Catalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell command
  injection (RCE) via PDF render options.


  Options are passed directly to the wkhtmltopdf command without sanitization.


  Any web application that passes user-co…
severity: none
cwe:
  - CWE-78
published: '2026-07-25'
updated: '2026-07-25'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-16766'
references:
  - url: 'https://github.com/mc7244/Catalyst-View-Wkhtmltopdf/issues/6'
    label: 9b29abf9-4ab0-4765-b253-1875cd9b441e
  - url: >-
      https://github.com/robrwo/Catalyst-View-Wkhtmltopdf/security/advisories/GHSA-42w4-jj8w-6p98
    label: 9b29abf9-4ab0-4765-b253-1875cd9b441e
  - url: 'https://metacpan.org/release/RRWO/Catalyst-View-Wkhtmltopdf-v0.6.1/changes'
    label: 9b29abf9-4ab0-4765-b253-1875cd9b441e
  - url: 'http://www.openwall.com/lists/oss-security/2026/07/25/4'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.02574
epssPercentile: 0.84514
ingestedAt: '2026-07-26T11:12:02.890Z'
---

## Overview

Catalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell command injection (RCE) via PDF render options.

Options are passed directly to the wkhtmltopdf command without sanitization.

Any web application that passes user-controlled options such as the page_size, orientation or margins without validation allows shell command injection.

Version 0.6.0 was released with an incomplete fix for this issue.

Note that the wkhtmltopdf project is no longer being developed, and users of this package should migrate to alternative solutions.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
