Description
Affected versions of Flowintel allow attacker-controlled note content to be processed by Pandoc and XeLaTeX during PDF export in a way that can cause local files on the Flowintel server to be read and incorporated into the generated export.
Published: 2026-08-27
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Affected versions of Flowintel allow an attacker to inject content into a note that is processed by Pandoc and XeLaTeX during PDF export. The processing can read local files on the Flowintel server and embed those files into the generated PDF. This flaw is a classic local file read (CWE-22) that can lead to the disclosure of confidential data such as configuration files, credentials, or other sensitive files stored on the server, thereby compromising confidentiality.

Affected Systems

The vulnerability affects the Flowintel application distributed by Flowintel. No specific version numbers are listed in the advisory; any version prior to the fix is considered susceptible.

Risk and Exploitability

The CVSS score of 7.1 indicates high severity. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector requires an attacker to supply note content that triggers a PDF export – which could be achieved via a public or authenticated interface that allows note creation or editing. Once the export is triggered, Pandoc/XeLaTeX reads arbitrary server files, enabling confidential data disclosure. The risk is significant in environments where Flowintel services are exposed, and the lack of current exploit evidence or KEV status does not diminish the potential impact of the identified local file read. The vulnerability remains a critical concern until patched or mitigated.

Generated by OpenCVE AI on August 27, 2026 at 14:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest Flowintel release or apply the vendor patch that prevents arbitrary file reads during PDF export
  • If a patch is unavailable, disable the PDF export functionality or restrict it to users with strict authorization
  • Configure the Flowintel application process or the underlying Pandoc/XeLaTeX invocation to run with the minimal filesystem permissions necessary, preventing access to sensitive directories

Generated by OpenCVE AI on August 27, 2026 at 14:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 27 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Flowintel
Flowintel flowintel
Vendors & Products Flowintel
Flowintel flowintel

Thu, 27 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
Description Affected versions of Flowintel allow attacker-controlled note content to be processed by Pandoc and XeLaTeX during PDF export in a way that can cause local files on the Flowintel server to be read and incorporated into the generated export.
Title Flowintel Note PDF Export Allows Arbitrary Local File Read via Pandoc/XeLaTeX Processing
Weaknesses CWE-22
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Flowintel Flowintel
cve-icon MITRE

Status: PUBLISHED

Assigner: CIRCL

Published:

Updated: 2026-08-27T15:56:07.807Z

Reserved: 2026-08-27T10:04:56.022Z

Link: CVE-2026-81659

cve-icon Vulnrichment

Updated: 2026-08-27T15:56:04.911Z

cve-icon NVD

Status : Received

Published: 2026-08-27T13:18:42.190

Modified: 2026-08-27T17:20:55.723

Link: CVE-2026-81659

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-27T14:45:17Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')