CVE-2026-36576
Critical severity, CVSS 9.8. EPSS: 3% chance of exploitation in the next 30 days.
An OS command injection vulnerability in the app.py component of openlabs docker-wkhtmltopdf-aas up to commit 9f50579 allows attackers to execute arbitrary commands via a crafted POST request.
Published 2026-06-03. Last modified 2026-07-22.