Junglewise Threat Intelligence

CVE-2026-82866: @pdfme/common before 5.5.10 contains a server-side request forgery vulnerability in the getB64BasePdf function that fetches arbitrary URLs w

CVE-2026-82866 · Severity: medium · CVSS 6.8 · Published 2026-08-31

Vendors: PDFME, npm.

Executive brief

PDFME is a popular open-source PDF generation library used in web applications. The library's PDF generation function can be forced to make network requests to attacker-specified URLs when processing user-supplied templates, potentially exposing cloud credentials, internal APIs, and network topology. This poses a critical risk for web services accepting user-provided PDF templates.

Technical details

The vulnerability exists in the getB64BasePdf function in @pdfme/common (packages/common/src/helper.ts:130-141), which accepts a basePdf parameter and fetches arbitrary URLs via fetch() without any validation. When basePdf is a non-data-URI string and window is defined, the function passes it directly to fetch() with no URL allowlist, protocol restrictions, or private IP filtering. An attacker who can control the basePdf field in a template—either through a web application accepting user-supplied templates, or indirectly through template injection—can trigger SSRF attacks. Attack preconditions: the application must call generate() or related functions with attacker-controlled template data. The vulnerability affects SSR environments (Next.js, Nuxt, Cloudflare Workers) where window is polyfilled and fetch has unrestricted network access. Patches are available in version 5.5.10 and later.

Affected products

  • PDFME @pdfme/common <=5.5.9

Timeline

  • 2026-03-20: disclosed
  • 2026-03-20: patched: Version 5.5.10 and later

References

Related threats