GHSA-9jjj-7qhf-c5f9High

Affected versions of Flowintel allow attacker-controlled note content to be processed by Pandoc...

Published
August 27, 2026
Last Modified
August 27, 2026

🔗 CVE IDs covered (1)

📋 Description

Affected versions of Flowintel allow attacker-controlled note content to be processed by Pandoc and XeLaTeX during PDF export in a way that can cause local files on the Flowintel server to be read and incorporated into the generated export.

🔗 References (4)