CVE-2025-51591
A Server-Side Request Forgery (SSRF) in JGM Pandoc v3.6.4 allows attackers to gain access to and compromise the whole infrastructure via injecting a crafted iframe. Note: Some users have stated that Pandoc by default can retrieve and parse untrusted HTML content which can enable SSRF vulnerabilities. Using the ‘--sandbox’ option or ‘pandoc-server’ can mitigate such vulnerabilities. Using pandoc with an external ‘--pdf-engine’ can also enable SSRF vulnerabilities, such as CVE-2022-35583 in wkhtmltopdf.
- Fix
- Available
- CVSS 3.1
- 3.7 LOW
- EPSS
- 0.6% (46th percentile)
- Weakness
- CWE-918
- NVD status
- Deferred
- Published
- 2025-07-11
CVE-2025-51591 at NVD
1 known exploit for CVE-2025-51591
Proof-of-concept code and exploit modules indexed by Sploitus