CVE-2026-36576
the affected product
An OS command injection vulnerability in the app.py component of openlabs docker-wkhtmltopdf-aas up to commit 9f50579 allows attackers to execute arbitrary commands via a crafted POST request.
- CVSS
- 9.8
- EPSS
- 1.49% 71.6% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.04