CVE-2025-56590
Critical · CVSS 9.8Apryse HTML2PDF SDK — OS Command Injection / Argument Injection RCE (CWE-78)
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- other
- CWE-78
Description
An issue was discovered in the InsertFromURL() function of the Apryse HTML2PDF SDK thru 11.10. This vulnerability could allow an attacker to execute arbitrary operating system commands on the local server.
Search profile — drives PoC discovery
Symbols InsertFromURLHTML2PDFhtml2pdfInsertFromURL()
Keywords CVE-2025-56590Apryse HTML2PDFInsertFromURLargument injectionRCEOS command injectionApryse SDKHTML2PDF RCEApryse server-sidestratascale apryse
Versions: thru 11.10
References
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-06T06:30:39.000Z