Impact
Affected versions of Flowintel allow an attacker to inject content into a note that is processed by Pandoc and XeLaTeX during PDF export. The processing can read local files on the Flowintel server and embed those files into the generated PDF. This flaw is a classic local file read (CWE-22) that can lead to the disclosure of confidential data such as configuration files, credentials, or other sensitive files stored on the server, thereby compromising confidentiality.
Affected Systems
The vulnerability affects the Flowintel application distributed by Flowintel. No specific version numbers are listed in the advisory; any version prior to the fix is considered susceptible.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector requires an attacker to supply note content that triggers a PDF export – which could be achieved via a public or authenticated interface that allows note creation or editing. Once the export is triggered, Pandoc/XeLaTeX reads arbitrary server files, enabling confidential data disclosure. The risk is significant in environments where Flowintel services are exposed, and the lack of current exploit evidence or KEV status does not diminish the potential impact of the identified local file read. The vulnerability remains a critical concern until patched or mitigated.
OpenCVE Enrichment