PT-2026-52661 · Rapid7 · Insightconnect Markdown Plugin
Publicado
2026-06-26
·
Atualizado
2026-06-26
·
CVE-2026-8661
CVSS v3.1
4.8
Média
| Vetor | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N |
Server-Side Cross-Site Scripting and Server-Side Request Forgery vulnerability in the markdown to pdf action of Rapid7 InsightConnect Markdown Plugin version 3.1.4 and earlier on Linux allows remote attackers to execute JavaScript server-side and make arbitrary outbound HTTP requests via crafted content embedded in Markdown input. The PDF rendering engine does not restrict script execution or outbound network access.
Correção
SSRF
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Insightconnect Markdown Plugin