Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 31 Aug 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | @pdfme/common before 5.5.10 contains a server-side request forgery vulnerability in the getB64BasePdf function that fetches arbitrary URLs without validation when basePdf is attacker-controlled. Attackers who control the basePdf template field can force servers or clients to make requests to internal endpoints, enabling metadata exfiltration, network reconnaissance, and blind request forgery attacks. | |
| Title | @pdfme/common before 5.5.10 SSRF via Unvalidated URL Fetch | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-31T08:46:36.781Z
Reserved: 2026-08-31T08:37:53.170Z
Link: CVE-2026-82866
No data.
Status : Received
Published: 2026-08-31T09:17:07.260
Modified: 2026-08-31T09:17:07.260
Link: CVE-2026-82866
No data.
OpenCVE Enrichment
No data.