@pdfme/common before 5.5.10 contains a server-side request forgery vulnerability in the getB64BasePdf function that fetches arbitrary URLs without validation when basePdf is attacker-controlled. Attackers who control the basePdf template field can force servers or clients to make requests to internal endpoints, enabling metadata exfiltration, network reconnaissance, and blind request forgery attacks.
Metrics
Affected Vendors & Products
References
History
Wed, 02 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 31 Aug 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pdfme
Pdfme common |
|
| Vendors & Products |
Pdfme
Pdfme common |
Mon, 31 Aug 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | @pdfme/common before 5.5.10 contains a server-side request forgery vulnerability in the getB64BasePdf function that fetches arbitrary URLs without validation when basePdf is attacker-controlled. Attackers who control the basePdf template field can force servers or clients to make requests to internal endpoints, enabling metadata exfiltration, network reconnaissance, and blind request forgery attacks. | |
| Title | @pdfme/common before 5.5.10 SSRF via Unvalidated URL Fetch | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-08-31T08:46:36.781Z
Updated: 2026-09-02T15:34:50.077Z
Reserved: 2026-08-31T08:37:53.170Z
Link: CVE-2026-82866
Updated: 2026-09-02T15:34:09.467Z
Status : Deferred
Published: 2026-08-31T09:17:07.260
Modified: 2026-09-10T15:53:23.707
Link: CVE-2026-82866
No data.