Pathling Server Vulnerability in FHIR Integration Tools by Aehrc
CVE-2026-47664
What is CVE-2026-47664?
The Pathling Server, a toolset designed for seamless integration with FHIR and clinical terminology in health data analytics, has a vulnerability in its $import-pnp operation. This flaw allows an attacker to supply an exportUrl that could point to an untrusted remote FHIR Bulk Export endpoint without adequate validation. As a result, the server can create a bulk-export client based on user-provided credentials and download files from any specified host, effectively bypassing the established allowableSources allowlist designed to ensure secure file imports. The latest version, 2.0.0, addresses this vulnerability. Users are advised to either update to this version or disable the $import-pnp operation to mitigate potential risks.
Affected Version(s)
pathling < 2.0.0
