CVE-2026-81659
Received Received - Intake

Path Traversal in Flowintel PDF Export via Pandoc and XeLaTeX

Vulnerability report for CVE-2026-81659, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-27

Last updated on: 2026-08-27

Assigner: CIRCL

Description

Affected versions of Flowintel allow attacker-controlled note content to be processed by Pandoc and XeLaTeX during PDF export in a way that can cause local files on the Flowintel server to be read and incorporated into the generated export.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-27
Last Modified
2026-08-27
Generated
2026-08-27
AI Q&A
2026-08-27
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
flowintel flowintel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Flowintel allows attackers to craft malicious note content that, when exported as a PDF or DOCX, can cause the server to read and include arbitrary local files in the generated export. The issue stems from unsafe processing of note content by Pandoc and XeLaTeX during export.

Detection Guidance

Check for unauthorized PDF or DOCX exports from Flowintel that may indicate exploitation. Review server logs for suspicious note content containing file path references like ../ or absolute paths. Inspect temporary files created during export processes for unexpected content.

Impact Analysis

An attacker could exploit this to access sensitive files on the Flowintel server, potentially exposing confidential data such as system files, user credentials, or other restricted information. This could lead to further attacks or data breaches.

Compliance Impact

This vulnerability could violate compliance requirements under GDPR and HIPAA by enabling unauthorized access to personal or protected health information stored on the server. Organizations using Flowintel may face legal penalties or reputational damage if exploited.

Mitigation Strategies

Update Flowintel to the patched version. Restrict export formats to PDF and DOCX only. Disable shell escape features in Pandoc. Set restrictive environment variables for PDF generation. Monitor for unusual export activities.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-81659. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart