PT-2026-24364 · Pdfmake · Pdfmake
Mario Pepe
·
Published
2026-03-10
·
Updated
2026-03-23
·
CVE-2026-26801
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
pdfmake versions 0.3.0-beta.2 through 0.3.5
Description
A Server-Side Request Forgery (SSRF) issue exists in the
src/URLResolver.js component of pdfmake. This allows a remote attacker to potentially obtain sensitive information. The issue was addressed with the release of version 0.3.6, which introduces the setUrlAccessPolicy() method. This method allows server operators to define URL access rules. A warning is now logged when pdfmake is used server-side without a policy configured.Recommendations
Update to pdfmake version 0.3.6 or later.
Configure URL access rules using the
setUrlAccessPolicy() method.Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pdfmake