Server-Side Request Forgery Vulnerability in @pdfme/common Software
CVE-2026-82866
8.9HIGH
What is CVE-2026-82866?
@pdfme/common versions prior to 5.5.10 are susceptible to a server-side request forgery vulnerability in the getB64BasePdf function. This flaw permits attackers to supply unvalidated basePdf template fields, enabling unauthorized access to internal endpoints. Such exploitation can lead to metadata exfiltration and blind request forgery attacks, posing significant security risks to affected systems.
Affected Version(s)
common 0 < 5.5.10
common 5.5.10
