{"id":"CVE-2026-81659","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-81659","summary":"Flowintel Note PDF Export Allows Arbitrary Local File Read via Pandoc/XeLaTeX Processing","details":"Affected versions of Flowintel allow attacker-controlled note content to be processed by Pandoc and XeLaTeX during PDF export in a way that can cause local files on the Flowintel server to be read and incorporated into the generated export.","published":"2026-08-27T10:07:30.269Z","modified":"2026-08-28T03:47:29.253761594Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/flowintel/flowintel/commit/16f618fa36a72c4c5ca3ff0abf7dd67455318ef1","label":"flowintel/flowintel@16f618f"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/81xxx/CVE-2026-81659.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-81659"},{"type":"FIX","url":"https://github.com/flowintel/flowintel/commit/16f618fa36a72c4c5ca3ff0abf7dd67455318ef1"},{"type":"FIX","url":"https://github.com/flowintel/flowintel/commit/2ba9700a5473223639575050bda607f498add7c6"},{"type":"PACKAGE","url":"https://github.com/flowintel/flowintel"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-28T03:47:29.253761594Z"}}