[CYBERDIGEST]
⊞ Dashboard ⚡ Intelligence 📝 Reports 📚 Global Threats 💻 Hack Lab 🗄️ Resources ⌬ 0xJerry's Lab
📡 RSS Feed
System Online

Tag

#Perl

articleCRITICAL 9.0

Critical Shell Command Injection Vulnerability in Catalyst::View::Wkhtmltopdf

A critical vulnerability (CVE-2026-16766) has been discovered in Catalyst::View::Wkhtmltopdf versions before 0.6.1, allowing for shell command injection via PDF render options. This vulnerability is particularly severe as it enables remote code execution (RCE) without authentication. The affected package is no longer actively developed, and users are urged to migrate to alternative solutions. Immediate patching or migration is strongly recommended to prevent potential exploitation.

Jul 26, 20261 source
articleCRITICAL 9.1

Critical CSRF Vulnerability in Mojolicious::Plugin::Web::Auth::OAuth2 (CVE-2026-9733)

A critical vulnerability (CVE-2026-9733) with a CVSS score of 9.1 has been discovered in Mojolicious::Plugin::Web::Auth::OAuth2 versions up to 0.17. This vulnerability allows an attacker to hijack another user's session through cross-site request forgery (CSRF) due to a predictable state parameter. The vulnerability has not been actively exploited but poses a significant risk due to its high severity and potential impact. Immediate patching or mitigation is recommended.

Jun 24, 20261 source