CVE-2026-81659: Flowintel Note PDF Export Allows Arbitrary Local File Read via Pandoc/XeLaTeX Processing
Affected versions of Flowintel allow attacker-controlled note content to be processed by Pandoc and XeLaTeX during PDF export in a way that can cause local files on the Flowintel server to be read and incorporated into the generated export.
Affected Software
Event History
Frequently Asked Questions
Who can realistically exploit this issue?
An attacker needs the ability to supply or modify note content that will be processed during a PDF export. Systems where untrusted users can create or edit notes and trigger, or persuade another user to trigger, PDF exports are exposed.
What must occur for the vulnerable processing to run?
The attacker-controlled note content must be processed by Pandoc and XeLaTeX as part of a PDF export. The issue is tied to the export workflow rather than ordinary note viewing.
What is the potential impact?
Local files readable by the Flowintel server process can be read and incorporated into the generated PDF export. The available information does not establish that files can be modified or that code execution is possible.