Executive brief
KnpLabs Snappy is a PHP library used to generate PDFs and images from web pages. A security flaw allows attackers to execute unauthorized commands on the server if they can influence the configuration path of the underlying conversion tool. This could lead to a full system compromise or unauthorized access to sensitive data handled by the web application.
Technical details
A command injection vulnerability exists in KnpLabs Snappy prior to version 1.7.1 on POSIX systems. The library attempts to escape the binary path using escapeshellarg(), but subsequently checks the escaped string with is_executable(). Because is_executable() fails on the quoted string, the library falls back to using the raw, unescaped path. If an attacker can influence the binary path via configuration, environment variables, or request data, they can append malicious shell commands (e.g., using semicolons). This results in arbitrary command execution with the privileges of the PHP process. The issue is patched in version 1.7.1.
Affected products
- KnpLabs knp-snappy <= 1.7.0
Timeline
- 2026-05-15: patched: Version 1.7.1 released
- 2026-05-15: advisory: GitHub Security Advisory GHSA-vpr4-p6fq-85jc published
- 2026-06-10: disclosed: CVE-2026-46643 published