Home

Description

An OS command injection vulnerability in the app.py component of openlabs docker-wkhtmltopdf-aas up to commit 9f50579 allows attackers to execute arbitrary commands via a crafted POST request.

PUBLISHED Reserved 2026-04-06 | Published 2026-06-03 | Updated 2026-06-03 | Assigner mitre

References

github.com/openlabs/docker-wkhtmltopdf-aas/issues/36 exploit

github.com/openlabs/docker-wkhtmltopdf-aas/issues/36

github.com/openlabs/docker-wkhtmltopdf-aas

github.com/...f505797671c3339520dec5fc01dff3a6f324f2e/app.py

hub.docker.com/r/openlabs/docker-wkhtmltopdf-aas

cve.org (CVE-2026-36576)

nvd.nist.gov (CVE-2026-36576)

Download JSON