Executive brief
The Rapid7 InsightConnect Markdown Plugin, which is used to convert text between different formats like HTML and PDF, contains a security flaw in its PDF conversion feature. An attacker can use specially crafted content to force the server to execute malicious scripts or make unauthorized network requests to other internal systems. This could lead to the exposure of sensitive internal data or unauthorized access to private network resources.
Technical details
A vulnerability exists in the markdown_to_pdf action of the Rapid7 InsightConnect Markdown Plugin (version 3.1.4 and earlier) due to insufficient restrictions in the underlying PDF rendering engine. Remote attackers can provide crafted Markdown input that triggers the execution of arbitrary JavaScript on the server or initiates unauthorized outbound HTTP requests (SSRF). The root cause is the failure to disable script execution and restrict network access during the Pandoc-based conversion process. This allows for potential data exfiltration from the local environment or internal network scanning. The issue is addressed in version 4.0.0 by disabling JavaScript execution.
Affected products
- Rapid7 InsightConnect Markdown Plugin <= 3.1.4
Timeline
- 2026-02-12: patched: Pull request merged to disable JS execution and bump SDK
- 2026-06-26: disclosed: CVE published to NVD