CVE-2025-51591
⚪ Do wiadomości
Podatność SSRF w JGM Pandoc umożliwia atakującym dostęp do całej infrastruktury.
CVSS
3.7
EPSS
0.6%
Exploit
none
Vendor
Opis źródłowy (NVD)
A Server-Side Request Forgery (SSRF) in JGM Pandoc v3.6.4 allows attackers to gain access to and compromise the whole infrastructure via injecting a crafted iframe. Note: Some users have stated that Pandoc by default can retrieve and parse untrusted HTML content which can enable SSRF vulnerabilities. Using the ‘--sandbox’ option or ‘pandoc-server’ can mitigate such vulnerabilities. Using pandoc with an external ‘--pdf-engine’ can also enable SSRF vulnerabilities, such as CVE-2022-35583 in wkhtmltopdf.
ssrf
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 3.7 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.6% |
| Opublikowano (NVD) | 2025-07-11 14:15:27 UTC |
| Ostatnia modyfikacja (NVD) | 2026-07-05 17:17:15 UTC |
Referencje
- https://github.com/RealestName/Vulnerability-Research/tree/main/CVE-2025-51591 (cve@mitre.org)
- https://github.com/jgm/pandoc/discussions/11200 (cve@mitre.org)
- https://github.com/jgm/pandoc/issues/10682 (cve@mitre.org)
- https://github.com/jgm/pandoc/issues/11261 (cve@mitre.org)
- https://github.com/jgm/pandoc/issues/8874 (cve@mitre.org)
- https://github.com/jgm/pandoc/pull/11262 (cve@mitre.org)
- https://www.wiz.io/blog/imds-anomaly-hunting-zero-day (cve@mitre.org)
- https://github.com/jgm/pandoc/commit/67edf7ce7cd3563a180ae44bd122b012e22364f8 (134c704f-9b21-4f2e-91b3-4a467353bcc0)
- https://pandoc.org (134c704f-9b21-4f2e-91b3-4a467353bcc0)
- not-applicable:http://jgm.com/ (134c704f-9b21-4f2e-91b3-4a467353bcc0)
- not-applicable:http://pandoc.com/ (134c704f-9b21-4f2e-91b3-4a467353bcc0)