MEDIUM6.1npm
GHSA-54xv-94qv-2gfg· CVE-2025-53626@pdfme/common vulnerable to to XSS and Prototype Pollution through its expression evaluation
Modified: 9/10/2026
package
pkg:npm/%40pdfme/common
@pdfme/common vulnerable to to XSS and Prototype Pollution through its expression evaluation
Modified: 9/10/2026
PDFME has SSRF via Unvalidated URL Fetch in `getB64BasePdf` When `basePdf` Is Attacker-Controlled
Modified: 9/1/2026