VDB
Sign up
CRITICAL9.8

GHSA-rhwx-hjx2-x4qr

PDFKit vulnerable to Command Injection

Quick fix

GHSA-rhwx-hjx2-x4qr — pdfkit: upgrade to the fixed version with the command below.

bundle update pdfkit

Details

The package pdfkit is vulnerable to Command Injection where the URL is not properly sanitized.

Note: This issue was patched in 0.8.7.2, but the patch was discovered to be ineffective. The updated patch version is 0.8.7.2.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/pdfkit
Introduced in: 0Fixed in: 0.8.7.2
Fixbundle update pdfkit

References