QID 981967
QID 981967: Nodejs (npm) Security Update for html-pdf (GHSA-x4w5-r546-x9qh)
All versions of `html-pdf` are vulnerable to Arbitrary File Read. The package fails to sanitize the HTML input, allowing attackers to exfiltrate server files by supplying malicious HTML code. XHR requests in the HTML code are executed by the server. Input with an XHR request such as `request.open("GET","file:///etc/passwd")` will result in a PDF document with the contents of `/etc/passwd`.
## Recommendation
No fix is currently available. There is a mitigation available in the provided reference.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-x4w5-r546-x9qh for updates pertaining to this vulnerability.
Vendor References
- GHSA-x4w5-r546-x9qh -
github.com/advisories/GHSA-x4w5-r546-x9qh
CVEs related to QID 981967
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-x4w5-r546-x9qh | html-pdf |
|