{"id":"GHSA-5p98-wpc9-g498","summary":"Server-Side Request Forgery in html-pdf-chrome","details":"## Recommendation\nThis package is working as intended. A [Security](https://github.com/westy92/html-pdf-chrome#security) section has been added since v0.6.1 to detail proper usage of this library. Npm has revoked their advisory altogether.\n\n## Original Advisory\nAll versions of `html-pdf-chrome` are vulnerable to Server-Side Request Forgery (SSRF). The package executes HTTP requests if the parsed HTML contains external references to resources, such as `\u003ciframe src=\"http://localhost\" height=\"800px\" width=\"800px\"\u003e\u003c/iframe\u003e`. This allows attackers to access resources through HTTP that are accessible to the server, including private resources in the hosting environment.","modified":"2022-06-22T19:28:32Z","published":"2020-09-04T15:21:32Z","database_specific":{"cwe_ids":["CWE-918"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2020-08-31T18:55:39Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/westy92/html-pdf-chrome/issues/249"},{"type":"PACKAGE","url":"https://github.com/westy92/html-pdf-chrome"},{"type":"WEB","url":"https://www.npmjs.com/advisories/1339"}],"affected":[{"package":{"name":"html-pdf-chrome","ecosystem":"npm","purl":"pkg:npm/html-pdf-chrome"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.6.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-5p98-wpc9-g498/GHSA-5p98-wpc9-g498.json"}}],"schema_version":"1.9.0"}