Arbitrary File Read Vulnerability in OpenEMR Affected by Unescaped HTML Handling
CVE-2026-33301
7.1HIGH
What is CVE-2026-33301?
OpenEMR, a free and open-source electronic health records management application, has a vulnerability that allows users with the 'Notes - my encounters' role to submit Eye Exam forms. This vulnerability arises during the PDF creation process, where form responses are interpreted as unescaped HTML. As a result, an attacker could potentially include arbitrary image files from the server within the generated PDF, posing significant security risks. The issue is resolved in version 8.0.0.2.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
openemr < 8.0.0.2
