PT-2026-24364 · Pdfmake · Pdfmake

Mario Pepe

·

Published

2026-03-10

·

Updated

2026-03-23

·

CVE-2026-26801

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions pdfmake versions 0.3.0-beta.2 through 0.3.5
Description A Server-Side Request Forgery (SSRF) issue exists in the src/URLResolver.js component of pdfmake. This allows a remote attacker to potentially obtain sensitive information. The issue was addressed with the release of version 0.3.6, which introduces the setUrlAccessPolicy() method. This method allows server operators to define URL access rules. A warning is now logged when pdfmake is used server-side without a policy configured.
Recommendations Update to pdfmake version 0.3.6 or later. Configure URL access rules using the setUrlAccessPolicy() method.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2026-26801
GHSA-WP52-R2FP-4VMR

Affected Products

Pdfmake