MEDIUMVulnerability

CVE-2026-82866

@pdfme/common before 5.5.10 contains a server-side request forgery vulnerability in the getB64BasePdf function that fetches arbitrary URLs without validation when basePdf is attacker-controlled. Attackers who control the basePdf template field can force servers or clients to make requests to internal endpoints, enabling metadata exfiltration, network reconnaissance, and blind request forgery attacks.

Properties

severity
MEDIUM
score
6.8
epss_score
0.00217
cve_id
CVE-2026-82866
vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
published_at
2026-08-31T09:17:07.260
last_modified
2026-09-02T16:17:27.003
epss_percentile
0.12049

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Server-Side Request Forgery (SSRF)

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-82866 — Ninja Signal Threat Intelligence | Ninja Signal