PatchSiren

pdfme CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH pdfme CVE published 2026-08-31

CVE-2026-82866

The @pdfme/common library before version 5.5.10 contains a server-side request forgery vulnerability in the getB64BasePdf function. This vulnerability allows attackers to fetch arbitrary URLs without validation when the basePdf template field is attacker-controlled, potentially leading to metadata exfiltration, network reconnaissance, and blind request forgery attacks. Affected product deployments should [truncated]

LOW pdfme CVE published 2026-08-31

CVE-2026-82865

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-31T09:17:07.110Z and has not been modified since then. The vulnerability affects pdfme schemas before version 5.5.10 and involves a cross-site scripting issue in the multiVariableText property panel. This vulnerability allows attackers to inject arbitrary JavaScript when users open the Designer and [truncated]

HIGH pdfme CVE published 2026-08-31

CVE-2026-82864

CVE-2026-82864 is a denial-of-service vulnerability in pdf-lib versions before 5.5.10. The issue is caused by an unbounded buffer growth vulnerability in the DecodeStream.ensureBuffer() method, which allows attackers to cause denial of service by supplying a crafted PDF with a FlateDecode stream containing a decompression bomb. This vulnerability can lead to memory exhaustion and potential crashes in Node [truncated]