VDB
Sign up
HIGH8.2

GHSA-hcq6-h8v2-r5wm

Server-Side Request Forgery in node-pdf-generator

Details

This affects all versions of package node-pdf-generator up to and including 0.0.6. Due to lack of user input validation and sanitization done to the content given to node-pdf-generator, it is possible for an attacker to craft a url that will be passed to an external server allowing an SSRF attack.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/node-pdf-generator
Introduced in: 0

No fixed version published yet for node-pdf-generator (npm). Pin to a known-safe version or switch to an alternative.

References