Skip to content

[GHSA-wp52-r2fp-4vmr] pdfmake is vulnerable to server-side request forgery (SSRF)#7189

Closed
mariopepe wants to merge 1 commit intomariopepe/advisory-improvement-7189from
mariopepe-GHSA-wp52-r2fp-4vmr
Closed

[GHSA-wp52-r2fp-4vmr] pdfmake is vulnerable to server-side request forgery (SSRF)#7189
mariopepe wants to merge 1 commit intomariopepe/advisory-improvement-7189from
mariopepe-GHSA-wp52-r2fp-4vmr

Conversation

@mariopepe
Copy link

Updates

  • References

Comments
I am the original discoverer of this vulnerability. I reported it to MITRE (CVE-2026-26801), coordinated the disclosure with the maintainer, and the fix was released in 0.3.6. Adding my writeup as a reference and requesting analyst credit for Mario Pepe (https://github.com/mariopepe).

@github-actions github-actions bot changed the base branch from main to mariopepe/advisory-improvement-7189 March 17, 2026 21:55
@mariopepe
Copy link
Author

Hi, could you please add the following credits block to this advisory? I am the original discoverer of CVE-2026-26801 — I reported it to MITRE, coordinated the fix with the maintainer, and the patch shipped in pdfmake 0.3.6.

"credits": [
  {
    "name": "Mario Pepe",
    "contact": [
      "https://github.com/mariopepe"
    ],
    "type": "FINDER"
  }
],

This follows the OSV 1.4.0 schema format, same as PRs #6397, #6229, and #6748.

Thank you.

@mariopepe
Copy link
Author

Closing in favor of a new PR from my fork that includes credits.

@mariopepe mariopepe closed this Mar 18, 2026
@github-actions github-actions bot deleted the mariopepe-GHSA-wp52-r2fp-4vmr branch March 18, 2026 07:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant