Junglewise Threat Intelligence

CVE-2025-51591: JGM Pandoc SSRF via crafted iframe in HTML reader

CVE-2025-51591 · Severity: low · CVSS 3.7 · Published 2025-07-11

Executive brief

JGM Pandoc, a widely used document conversion tool, is susceptible to a security flaw when processing untrusted HTML content. An attacker can provide a specially crafted document containing an iframe that forces the server to make unauthorized requests to internal systems. This could allow an attacker to view sensitive internal information or interact with private infrastructure that is not normally accessible from the internet.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in JGM Pandoc v3.6.4 due to the way the HTML reader handles iframe elements. By default, Pandoc may retrieve and parse remote content specified in an iframe, allowing an attacker to trigger outbound requests from the server to internal or restricted network resources. This is particularly impactful when Pandoc is used in automated environments to convert user-supplied HTML to other formats like PDF. While the maintainers view this as a configuration issue rather than a code bug, it can be mitigated by using the '--sandbox' flag or 'pandoc-server', which restricts network access. Documentation updates have been made to warn users about these risks when handling untrusted input.

Affected products

  • JGM Pandoc 3.6.4

Timeline

  • 2025-03-12: disclosed: Initial issue reported on GitHub regarding SSRF in PDF generation
  • 2025-05-01: other: Vulnerability discovered by Harel Levy
  • 2025-07-11: advisory: CVE-2025-51591 published
  • 2025-10-06: patched: Maintainer added security documentation and recommended sandbox mode as a mitigation

References