CVE-2022-25765
PDFKit vulnerable to Command Injection
9.8
CRITICAL
CVSS 3.1
EPSS 38.9%
Description
The package pdfkit is vulnerable to Command Injection where the URL is not properly sanitized. Note: This issue was patched in 0.8.7.2, but the patch was discovered to be ineffective. The updated patch version is 0.8.7.2.
How to fix CVE-2022-25765
To remediate CVE-2022-25765, upgrade the affected package to a fixed version below.
- RubyGems/pdfkit—upgrade to 0.8.7.2 or later
Is CVE-2022-25765 being exploited?
Moderate — EPSS is 38.9%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 0.8.7.2
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |