PT-2026-82491 · Pandoc+2 · Pandoc+2

·

CVE-2026-81659

·

Published

2026-08-27

·

Updated

2026-08-28

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Flowintel (affected versions not specified)
Description An issue exists where attacker-controlled note content is processed by Pandoc and XeLaTeX during PDF export. This can lead to the unauthorized reading of local files from the Flowintel server, which are then incorporated into the generated export file.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81659

Affected Products

Flowintel
Pandoc
Xelatex