{"id":"GHSA-5p98-wpc9-g498","aliases":[],"url":"https://o3.security/vulnerability/GHSA-5p98-wpc9-g498","summary":"Server-Side Request Forgery in html-pdf-chrome","details":"## Recommendation\nThis package is working as intended. A [Security](https://github.com/westy92/html-pdf-chrome#security) section has been added since v0.6.1 to detail proper usage of this library. Npm has revoked their advisory altogether.\n\n## Original Advisory\nAll versions of `html-pdf-chrome` are vulnerable to Server-Side Request Forgery (SSRF). The package executes HTTP requests if the parsed HTML contains external references to resources, such as `<iframe src=\"http://localhost\" height=\"800px\" width=\"800px\"></iframe>`. This allows attackers to access resources through HTTP that are accessible to the server, including private resources in the hosting environment.","published":"2020-09-04T15:21:32Z","modified":"2022-06-22T19:28:32Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"html-pdf-chrome","fixedVersion":"0.6.1"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/westy92/html-pdf-chrome/issues/249"},{"type":"PACKAGE","url":"https://github.com/westy92/html-pdf-chrome"},{"type":"WEB","url":"https://www.npmjs.com/advisories/1339"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2022-06-22T19:28:32Z"}}