CVE-2025-55161: Stirling-PDF SSRF via Markdown

CVE-2025-55161: Stirling-PDF SSRF via Markdown-渗透云记 - 专注于网络安全与技术分享
CVE-2025-55161: Stirling-PDF SSRF via Markdown
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2025-55161: Stirling-PDF ssrf via Markdown

漏洞描述

Stirling-PDF is a locally hosted web application that performs various operations on PDF files. Prior to version 1.1.0, when using the /api/v1/convert/markdown/pdf endpoint to convert Markdown to PDF, the backend calls a third-party tool to process it and includes a sanitizer for security sanitization which can be bypassed and result in SSRF.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享