GHSA-pgx6-7jcq-2qff
MODERATEThe getB64BasePdf function in @pdfme/common fetches arbitrary URLs via fetch() without any validation when basePdf is a non-data-URI string and window is defined. An attacker who can control the basePdf field of a template (e.g., through a web application that accepts user-supplied templates) can force the server or client to make requests to arbitrary internal or external endpoints, enabling Serv
- Affected
- >=0, <5.5.10, <= 5.5.9
- Fixed in
- 5.5.10
- Weakness
- CWE-918
- Published
- 2026-03-20
- Source
- osv