Collected research
Blind trust: what is hidden behind the process of creating your PDF file?
An audit of seven HTML-to-PDF libraries showing that attacker-supplied HTML, CSS or SVG crosses a trust boundary inside the renderer: path traversal embeds private server files into the returned PDF, image and stylesheet URLs give blind SSRF into internal networks, a destructor chain reached via unserialize deletes arbitrary files, and crafted data URIs pin a CPU core.
Record
- Researcher
- Aleksey Solovev
- Published by
- PT SWARM
- Topic
- Other
In the archive
Related sources
- jsPDF CVE-2025-29907 advisory Advisory
- jsPDF CVE-2025-57810 advisory Advisory
- Dompdf CVE-2026-56722 advisory Advisory
Tags
This page is the archive's own catalogue record. The research is the work of Aleksey Solovev, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .