PDFKit v0.8.6 Command Injection (CVE-2022-25765): Detection and Fix
The pdfkit v0.8.6 exploit is CVE-2022-25765, a command injection in the Ruby pdfkit gem where an unsanitized URL reaches the shell. How it works conceptually, how to detect it, and the fix.