Executive brief
Dompdf, a library used to convert HTML content into PDF documents, contains a vulnerability that allows an attacker to probe the server's filesystem. By submitting specially crafted SVG images, a malicious actor can determine whether specific files or directories exist on the underlying server. This could allow an attacker to map out the server's internal structure, potentially aiding in further, more targeted attacks.
Technical details
An information disclosure vulnerability exists in Dompdf (versions 3.1.5 and prior) due to improper handling of SVG `<image>` elements within data-URI encoded documents. When Dompdf renders a PDF containing a malicious SVG, an attacker can use the `href` or `xlink:href` attributes to reference local files (e.g., `file:///etc/passwd`). The library exhibits different behavioral outputs (such as specific PHP warnings or rendering differences) when a file exists versus when it does not. This 'oracle' allows an unauthenticated remote attacker to confirm the existence of sensitive files and directories on the backend filesystem. The issue is addressed in version 3.1.6 by improving how local URL references are resolved within data-URI SVG documents.
Affected products
- dompdf dompdf <= 3.1.5
Timeline
- 2026-07-20: patched: Fixed in version 3.1.6
- 2026-07-28: advisory: GitHub Security Advisory published