CVE-2025-55151: Stirling-PDF SSRF vulnerability on /api/v1/convert/file/pdf
Stirling-PDF is a locally hosted web application that performs various operations on PDF files. Prior to version 1.1.0, the "convert file to pdf" functionality (/api/v1/convert/file/pdf) uses LibreOffice's unoconvert tool for conversion, and SSRF vulnerabilities exist during the conversion process. This issue has been patched in version 1.1.0.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55151?
CVE-2025-55151 is classified as a moderate severity vulnerability due to the potential for SSRF attacks.
How do I fix CVE-2025-55151?
To fix CVE-2025-55151, upgrade Stirling-PDF to version 1.1.0 or later.
What are the impacts of CVE-2025-55151?
The impacts of CVE-2025-55151 include the potential for an attacker to manipulate requests to access unauthorized internal resources.
In which versions of Stirling-PDF does CVE-2025-55151 exist?
CVE-2025-55151 exists in Stirling-PDF prior to version 1.1.0.
Is CVE-2025-55151 a remote or local vulnerability?
CVE-2025-55151 is a local vulnerability, as it affects a locally hosted web application.