Junglewise Threat Intelligence

CVE-2026-81659: Flowintel arbitrary file read in PDF export via Pandoc

CVE-2026-81659 · Severity: info · CVSS 0 · Published 2026-08-27

Technologies: FlowIntel. Vendors: FlowIntel.

Executive brief

Flowintel is an intelligence and case management platform that allows users to export notes to PDF. A vulnerability in the note export feature allows attackers to insert specially crafted content that, when processed by Pandoc and XeLaTeX during PDF generation, can read arbitrary files from the Flowintel server and embed their contents into the exported document. This could expose sensitive configuration files, secrets, or other data stored on the server.

Technical details

The vulnerability is an arbitrary file read flaw in Flowintel's PDF export functionality. When user-controlled note content is processed by Pandoc and XeLaTeX without proper sanitization, an attacker can craft malicious markdown/LaTeX that instructs these tools to read files from the server filesystem and include them in the generated PDF. The attack is triggered when a user (or an attacker with access to create notes) exports a note to PDF. The vulnerable code did not properly restrict or escape content before passing it to Pandoc with raw LaTeX/HTML processing enabled. The fix involves adding restrictions to the Pandoc markdown format configuration and sanitizing input before export.

Affected products

  • Flowintel Flowintel prior to commit 16f618fa36a72c4c5ca3ff0abf7dd67455318ef1

Timeline

  • 2026-08-27: disclosed
  • 2026-08-12: patched: Security fix merged in commits 16f618f and 2ba9700 on GitHub

References

Related threats