Impact
When generating PDF files, this vulnerability allows an attacker to read arbitrary files from the filesystem by injecting malicious link element into the prepped RFCXML.
Workarounds
Test untrusted input with link elements with rel="attachment" before processing.
References
This is related to GHSA-cfmv-h8fx-85m7.
Impact
When generating PDF files, this vulnerability allows an attacker to read arbitrary files from the filesystem by injecting malicious link element into the prepped RFCXML.
Workarounds
Test untrusted input with
linkelements withrel="attachment"before processing.References
This is related to GHSA-cfmv-h8fx-85m7.