The @pdfme/common library before version 5.5.10 contains a server-side request forgery vulnerability in the getB64BasePdf function. This vulnerability allows attackers to fetch arbitrary URLs without validation when the basePdf template field is attacker-controlled, potentially leading to metadata exfiltration, network reconnaissance, and blind request forgery attacks. Affected product deployments should [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-31T09:17:07.110Z and has not been modified since then. The vulnerability affects pdfme schemas before version 5.5.10 and involves a cross-site scripting issue in the multiVariableText property panel. This vulnerability allows attackers to inject arbitrary JavaScript when users open the Designer and [truncated]
CVE-2026-82864 is a denial-of-service vulnerability in pdf-lib versions before 5.5.10. The issue is caused by an unbounded buffer growth vulnerability in the DecodeStream.ensureBuffer() method, which allows attackers to cause denial of service by supplying a crafted PDF with a FlateDecode stream containing a decompression bomb. This vulnerability can lead to memory exhaustion and potential crashes in Node [truncated]