The package pdfkit from 0.0.0 are vulnerable to Command Injection where the URL is not properly sanitized.
https://github.com/Jeanback1/exploit-vault
https://github.com/Jeanback1/CVE-2022-25765-exploit
https://github.com/GrandNabil/testpdfkit
https://github.com/PurpleWaveIO/CVE-2022-25765-pdfkit-Exploit-Reverse-Shell
https://github.com/CyberArchitect1/CVE-2022-25765-pdfkit-Exploit-Reverse-Shell
https://github.com/Atsukoro1/PDFKitExploit
https://github.com/advisories/GHSA-rhwx-hjx2-x4qr
https://security.snyk.io/vuln/SNYK-RUBY-PDFKIT-2869795
http://packetstormsecurity.com/files/171746/pdfkit-0.8.7.2-Command-Injection.html