CVE-2022-25765 is a command injection vulnerability in the pdfkit package (all versions from 0.0.0). The vulnerability arises because the URL input is not properly sanitized, allowing attackers to inject arbitrary commands into the underlying system call.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
8 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This is a small standalone Python proof-of-concept repository for CVE-2022-25765, described as a command-injection issue in pdfkit 0.8.6. It contains one executable Python script, a README, and a pinned requirements file. The script accepts a target URL plus callback host and port, performs a GET request to check whether the target returns HTTP 200, and then POSTs application/x-www-form-urlencoded data containing a url parameter engineered to reach a shell command injection sink. It Base64-encodes a Ruby command that starts a TCP reverse shell, constructs an injection string that decodes and executes that command through bash, and sends it to the user-selected target. requests and colorama are the only dependencies; requests TLS certificate verification is disabled for the exploit POST. There are no hard-coded victim domains, IP addresses, or callback addresses in the repository; all network destinations are operator supplied at runtime. The README references Hack The Box's Precious machine as a lab target and inconsistently calls the executable exploit2.py, while the actual entry-point filename is CVE-2022-25765.py.
This repository is a small standalone exploit project for CVE-2022-25765, a command injection vulnerability in the Ruby pdfkit gem affecting versions before 0.8.7.2. The repo contains four files: a Python exploit script, a README with technical background and usage examples, a requirements file, and a Dockerfile for reproducible execution. The main exploit logic is in exploit-CVE-2022-25765.py. It is a CLI tool written in Python that supports two primary capabilities: (1) generating a malicious pdfkit URL payload that executes an arbitrary operator-supplied command, and (2) generating a malicious payload that launches a Ruby reverse shell using TCPSocket to connect back to an attacker-controlled IP and port. A secondary capability is optional delivery: if the operator supplies -w and -p, the script sends the crafted payload to a target web application via HTTP POST using the specified parameter name, defaulting to 'url'. Operationally, the exploit does not exploit pdfkit locally by itself; it either prints a payload for manual insertion into vulnerable Ruby code paths or posts that payload to a remote web endpoint believed to pass user input into pdfkit. The payload format abuses the vulnerable handling of URL input by embedding a URL-encoded space followed by shell backticks. In reverse shell mode, the injected Ruby one-liner spawns sh and redirects I/O over a TCP connection to the attacker. Repository structure and purpose: - exploit-CVE-2022-25765.py: primary exploit entry point and only substantive code file. - README.md: vulnerability explanation, affected versions, exploitation examples, identification guidance, and mitigation notes. - requirements.txt: Python dependencies (requests, urllib3). - Dockerfile: builds an Ubuntu container with Python and Ruby tooling, installs pdfkit gem 0.8.6 and Python dependencies, and sets the exploit script as the container entrypoint. Notable implementation details: - Uses requests.post() to send the payload to a target website. - Requires both -w and -p together for web delivery mode. - Performs only minimal validation of the target URL and arguments. - Contains no automated vulnerability verification beyond sending the payload and reporting success optimistically. Overall, this is a real exploit/weaponization helper rather than a detector. It is best classified as OPERATIONAL: it includes a working payload and delivery mechanism, but customization is limited to command text, callback IP/port, target URL, and POST parameter.
This repository contains a proof-of-concept exploit for a command injection vulnerability in applications using the pdfkit library (commonly in Ruby) with wkhtmltopdf. The vulnerability arises when user-supplied URLs are passed unsanitized to PDFKit.new(), which then invokes wkhtmltopdf with the URL as a shell argument. If the URL contains shell metacharacters (such as backticks), arbitrary commands can be executed on the server. The exploit (poc.py) allows the user to generate a malicious URL payload that, when processed by a vulnerable server, will execute a specified command or open a reverse shell to the attacker's machine. The script can also send the payload to a target web application via HTTP POST if the relevant parameters are provided. The repository consists of a Python exploit script and a README explaining the vulnerability and attack scenario.
This repository provides a proof-of-concept exploit for CVE-2022-25765, a command injection vulnerability in pdfkit versions prior to 0.8.6. The exploit leverages unsanitized user input in a URL parameter to inject a Ruby reverse shell payload. The attacker is instructed to set up an HTTP server and a netcat listener to receive the shell. The main exploit is a crafted curl command that sends a POST request to a vulnerable server, causing it to execute the injected Ruby code and connect back to the attacker's listener. The repository consists of a README with usage instructions and a text file containing the exploit command. No detection scripts or fake elements are present; the repository is a functional proof-of-concept for remote code execution via network attack vector.
This repository contains a Python exploit script (CVE-2022-25765.py) and a README.md file. The exploit targets a command injection vulnerability in pdfkit versions prior to 0.8.6 (CVE-2022-25765). The script takes as input the target's HTTP address, the attacker's IP address, and a port (default 9001), then sends a crafted POST request to the target's HTTP endpoint. The payload leverages command injection to execute a bash reverse shell, connecting back to the attacker's machine. The README provides usage instructions and an example, including how to set up a netcat listener to catch the shell. The exploit is operational, providing a working reverse shell if the target is vulnerable and properly configured. No framework is used; the code is standalone Python.
This repository provides a Python exploit for CVE-2022-25765, a command injection vulnerability in the Ruby 'pdfkit' gem (versions < 0.8.7.2). The exploit allows an attacker to craft a malicious URL that, when processed by pdfkit, results in arbitrary command execution on the server. The main exploit script, 'exploit-CVE-2022-25765.py', supports generating payloads for both custom command execution and reverse shell access. It can either output the payload for manual use or send it directly to a web endpoint running a vulnerable pdfkit instance via HTTP POST. The repository includes a Dockerfile for setting up a test environment, a requirements.txt for Python dependencies (requests, urllib3), and a README.md with detailed usage instructions and background on the vulnerability. The exploit is operational, providing real payloads and automation for both local and remote exploitation scenarios. The main attack vector is network-based, targeting web applications that use pdfkit to process user-supplied URLs.
This repository contains a proof-of-concept exploit for CVE-2022-25765, a command injection vulnerability in pdfkit versions prior to 0.8.7.2. The repository consists of a README.md file with usage instructions and a single Python script (cve-2022-25765.py) that implements the exploit. The script takes a target URL, attacker's IP, and port as arguments, and sends a crafted HTTP POST request to the vulnerable server. The payload leverages command injection via the 'url' parameter to execute a Ruby one-liner that opens a reverse shell back to the attacker's machine. The exploit is network-based and requires the attacker to have a listener ready to catch the shell. The code is a functional proof-of-concept and does not include advanced features or payload customization.
This repository contains a proof-of-concept exploit for CVE-2022-25765, a Blind Remote Code Execution (RCE) vulnerability. The main file, poc.py, is a Python script that allows the user to specify a target URL and either a command to execute or parameters for a reverse shell. The exploit works by crafting a payload that injects a command into a vulnerable parameter (likely via server-side template or command injection) and sends it to the target via an HTTP POST request. The script supports both arbitrary command execution and reverse shell functionality. The README provides a brief description, and the code is self-contained, requiring only the requests library. No hardcoded endpoints are present except for the payload template, which uses 127.0.0.1 as an example. The exploit is operational and can be used against targets vulnerable to CVE-2022-25765.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.