CVE-2026-82866
8.9
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Summary
@pdfme/common before 5.5.10 contains a server-side request forgery vulnerability in the getB64BasePdf function that fetches arbitrary URLs without validation when basePdf is attacker-controlled. Attackers who control the basePdf template field can force servers or clients to make requests to internal endpoints, enabling metadata exfiltration, network reconnaissance, and blind request forgery attacks.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| pdfme | common | 0 < 5.5.10 | affected |
| pdfme | common | 5.5.10 | unaffected |
Weaknesses
- CWE-918: Server-Side Request Forgery (SSRF)
References
- https://github.com/pdfme/pdfme/security/advisories/GHSA-pgx6-7jcq-2qff
- https://www.vulncheck.com/advisories/pdfme-common-before-5.5.10-ssrf-via-unvalidated-url-fetch
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.