← volver
CVE-2026-82866highCWE-918

@pdfme/common before 5.5.10 SSRF via Unvalidated URL Fetch

21Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackcvss 8.9epss 0.2%
probabilidad de explotación
0.2%top 88% de las CVE
explotación observada
noninguna fuente lo reporta
@pdfme/common before 5.5.10 contains a server-side request forgery vulnerability in the getB64BasePdf function that fetches arbitrary URLs without validation when basePdf is attacker-controlled. Attackers who control the basePdf template field can force servers or clients to make requests to internal endpoints, enabling metadata exfiltration, network reconnaissance, and blind request forgery attacks.
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Productos afectados
pdfme · common