electron-pdf version 20.0.0 allows an external attacker to remotely obtain
arbitrary local files. This is possible because the application does not
validate the HTML content entered by the user.
                
            arbitrary local files. This is possible because the application does not
validate the HTML content entered by the user.
Metrics
Affected Vendors & Products
Advisories
    | Source | ID | Title | 
|---|---|---|
  EUVD | 
                EUVD-2024-0489 | electron-pdf version 20.0.0 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the HTML content entered by the user. | 
  Github GHSA | 
                GHSA-3jcv-5f9p-2f2p | Cross-site Scripting in electron-pdf | 
Fixes
    Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
        History
                    Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        
        epss
         
  | 
    
        
        
        epss
         
  | 
Wed, 12 Feb 2025 17:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Fraserxu
         Fraserxu electron-pdf  | 
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:fraserxu:electron-pdf:20.0.0:*:*:*:*:node.js:*:* | |
| Vendors & Products | 
        
        Fraserxu
         Fraserxu electron-pdf  | 
Status: PUBLISHED
Assigner: Fluid Attacks
Published:
Updated: 2024-08-01T18:48:21.883Z
Reserved: 2024-02-19T22:00:56.677Z
Link: CVE-2024-1648
Updated: 2024-08-01T18:48:21.883Z
Status : Analyzed
Published: 2024-02-20T01:15:07.943
Modified: 2025-02-12T17:02:43.703
Link: CVE-2024-1648
No data.
                        OpenCVE Enrichment
                    No data.
 EUVD
 Github GHSA