Metrics
Affected Vendors & Products
Mon, 24 Nov 2025 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Server-Side Request Forgery (SSRF) in JGM Pandoc v3.6.4 allows attackers to gain access to and compromise the whole infrastructure via injecting a crafted iframe. | A Server-Side Request Forgery (SSRF) in JGM Pandoc v3.6.4 allows attackers to gain access to and compromise the whole infrastructure via injecting a crafted iframe. Note: Some users have stated that Pandoc by default can retrieve and parse untrusted HTML content which can enable SSRF vulnerabilities. Using the ‘--sandbox’ option or ‘pandoc-server’ can mitigate such vulnerabilities. Using pandoc with an external ‘--pdf-engine’ can also enable SSRF vulnerabilities, such as CVE-2022-35583 in wkhtmltopdf. |
| References |
|
Tue, 07 Oct 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Wed, 24 Sep 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 15 Jul 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | pandoc: Server-Side Request Forgery in Pandoc | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
Fri, 11 Jul 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-918 | |
| Metrics |
cvssV3_1
|
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Server-Side Request Forgery (SSRF) in JGM Pandoc v3.6.4 allows attackers to gain access to and compromise the whole infrastructure via injecting a crafted iframe. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-07-11T00:00:00.000Z
Updated: 2025-11-24T21:52:10.536Z
Reserved: 2025-06-16T00:00:00.000Z
Link: CVE-2025-51591
Updated: 2025-07-11T14:34:34.529Z
Status : Awaiting Analysis
Published: 2025-07-11T14:15:27.347
Modified: 2025-11-24T22:15:48.747
Link: CVE-2025-51591