Web Hack List

Collected research

Blind trust: what is hidden behind the process of creating your PDF file?

An audit of seven HTML-to-PDF libraries showing that attacker-supplied HTML, CSS or SVG crosses a trust boundary inside the renderer: path traversal embeds private server files into the returned PDF, image and stylesheet URLs give blind SSRF into internal networks, a destructor chain reached via unserialize deletes arbitrary files, and crafted data URIs pin a CPU core.

Record

Researcher
Aleksey Solovev
Published by
PT SWARM
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Aleksey Solovev, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .