electron-pdf version 20.0.0 allows an external attacker to remotely obtain
arbitrary local files. This is possible because the application does not
validate the HTML content entered by the user.
Metrics
Affected Vendors & Products
References
History
Wed, 03 Dec 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:fraserxu:electron-pdf:*:*:*:*:*:*:*:* | |
| Metrics |
ssvc
|
Wed, 03 Dec 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | electron-pdf version 20.0.0 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the HTML content entered by the user. | electron-pdf version 20.0.0 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the HTML content entered by the user. |
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 12 Feb 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fraserxu
Fraserxu electron-pdf |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:fraserxu:electron-pdf:20.0.0:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Fraserxu
Fraserxu electron-pdf |
Status: PUBLISHED
Assigner: Fluid Attacks
Published: 2024-02-20T00:01:50.680Z
Updated: 2025-12-03T20:19:12.626Z
Reserved: 2024-02-19T22:00:56.677Z
Link: CVE-2024-1648
Updated: 2024-08-01T18:48:21.883Z
Status : Modified
Published: 2024-02-20T01:15:07.943
Modified: 2025-12-03T21:15:52.260
Link: CVE-2024-1648
No data.