PatchSiren cyber security CVE debrief
CVE-2026-82866 pdfme CVE debrief
The @pdfme/common library before version 5.5.10 contains a server-side request forgery vulnerability in the getB64BasePdf function. This vulnerability allows attackers to fetch arbitrary URLs without validation when the basePdf template field is attacker-controlled, potentially leading to metadata exfiltration, network reconnaissance, and blind request forgery attacks. Affected product deployments should be identified and owners assigned for follow-up. The CVE record was published on 2026-08-31T09:17:07.260Z and has not been modified since then. The vulnerability has a CVSS score of 8.9 and is classified as HIGH severity.
- Vendor
- pdfme
- Product
- common
- CVSS
- HIGH 8.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-31
- Original CVE updated
- 2026-08-31
- Advisory published
- 2026-08-31
- Advisory updated
- 2026-08-31
Who should care
Developers and administrators using @pdfme/common before version 5.5.10, as well as organizations relying on applications that utilize this library, should be aware of this vulnerability and take necessary steps to mitigate the risk. This includes reviewing and validating user-controlled input to the basePdf template field, implementing additional security measures to detect and prevent potential SSRF attacks, and prioritizing upgrades to a patched version of the library. Security teams and vulnerability management teams should also be aware of this vulnerability and track exceptions and retest remediated assets to ensure that the vulnerability is properly addressed. Operators and platform administrators should review compensating controls for exposed systems while remediation is scheduled and verified, and ensure that relevant monitoring, detection, and logs are in place for exposed assets that need extra review. Asset inventory and change management processes should also be reviewed to ensure that affected systems are properly tracked and remediated. Rollback and change window management processes should be implemented to ensure that changes are properly tested and validated before deployment. Source tracking and monitoring should also be implemented to detect and respond to potential exploitation attempts. Overall, a coordinated effort is required across development, operations, and security teams to properly address this vulnerability and minimize potential impact. The goal is to ensure that all stakeholders are aware of the vulnerability and are taking necessary steps to mitigate the risk and prevent potential attacks. This includes reviewing and updating incident response plans, conducting vulnerability assessments, and implementing additional security controls as needed. By prioritizing communication and coordination across teams, organizations can effectively address this vulnerability and reduce the risk of exploitation. Effective communication and coordination across teams are critical to ensuring that all stakeholders are aware of the vulnerability and are taking necessary steps to mitigate the risk and prevent potential attacks. This includes regular
Technical summary
The @pdfme/common library before version 5.5.10 contains a server-side request forgery vulnerability in the getB64BasePdf function. This vulnerability allows attackers to fetch arbitrary URLs without validation when the basePdf template field is attacker-controlled, potentially leading to metadata exfiltration, network reconnaissance, and blind request forgery attacks. The vulnerability is due to a lack of validation in the getB64BasePdf function, which can be exploited by attackers to make unauthorized requests. Organizations using @pdfme/common before version 5.5.10 should prioritize upgrading to a patched version to prevent potential server-side request forgery attacks.
Defensive priority
Organizations using @pdfme/common before version 5.5.10 should prioritize upgrading to a patched version to prevent potential server-side request forgery attacks.
Recommended defensive actions
- Upgrade to @pdfme/common version 5.5.10 or later
- Review and validate user-controlled input to the basePdf template field
- Implement additional security measures to detect and prevent potential SSRF attacks
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE description indicates that @pdfme/common before 5.5.10 contains a server-side request forgery vulnerability in the getB64BasePdf function. The vulnerability allows attackers to fetch arbitrary URLs without validation when the basePdf template field is attacker-controlled. However, the source detail is limited, and further verification is needed to confirm the affected scope and potential impact.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-82866 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-82866
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-82866 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-82866
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/pdfme/pdfme/security/advisories/GHSA-pgx6-7jcq-2qff
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/pdfme-common-before-5.5.10-ssrf-via-unvalidated-url-fetch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.