Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:36995
HistorySep 12, 2022 - 6:28 a.m.

Command Injection

2022-09-1206:28:55
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
36
vulnerable software
remote code execution
user input sanitization

EPSS

0.213

Percentile

96.5%

pdfkit is vulnerable to command injection. A remote attacker is able to execute malicious code on the system through a specifically crafted query string parameter due to the improper sanitization of user input in initialize function.