THREAT OPS › Threat News › CVE-2026-17431: PDF::WebKit versions through 1.2 for Perl allow OS command injection via a 2-arg open() of the output path in to_pdf and of stylesheet paths in _style_tag_for
CVE-2026-17431: PDF::WebKit versions through 1.2 for Perl allow OS command injection via a 2-arg open() of the output path in to_pdf and of stylesheet paths in _style_tag_for
<p>Posted by Robert Rothenberg on Aug 13</p>========================================================================<br /> CVE-2026-17431 CPAN Security Group<br /> ========================================================================<br /> <br /> CVE ID: CVE-2026-17431<br /> Distribution: PDF-WebKit<br /> Versions: through 1.2<br /> <b
Indicators of compromise
- CVE-2026-17431cve
- https://metacpan.org/dist/PDF-WebKiturl
Original source: https://seclists.org/oss-sec/2026/q3/493