HIGH8.2
GHSA-hcq6-h8v2-r5wm
Server-Side Request Forgery in node-pdf-generator
Details
This affects all versions of package node-pdf-generator up to and including 0.0.6. Due to lack of user input validation and sanitization done to the content given to node-pdf-generator, it is possible for an attacker to craft a url that will be passed to an external server allowing an SSRF attack.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/node-pdf-generator
Introduced in:
0No fixed version published yet for node-pdf-generator (npm). Pin to a known-safe version or switch to an alternative.