CVE-2026-36576

Published: Giu 03, 2026 Last Modified: Giu 03, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

An OS command injection vulnerability in the app.py component of openlabs docker-wkhtmltopdf-aas up to commit 9f50579 allows attackers to execute arbitrary commands via a crafted POST request.

https://github.com/openlabs/docker-wkhtmltopdf-aas
https://github.com/openlabs/docker-wkhtmltopdf-aas/blob/9f505797671c3339520dec5…
https://github.com/openlabs/docker-wkhtmltopdf-aas/issues/36
https://hub.docker.com/r/openlabs/docker-wkhtmltopdf-aas