CVE-2025-46568 - CVE House
Back to Database
Status published High CVE-2025-46568

Stirling-PDF Server-Side Request Forgery (SSRF)-Induced Arbitrary File Read Vulnerability

Vulnerability Description

Stirling-PDF is a locally hosted web application that allows you to perform various operations on PDF files. Prior to version 0.45.0, Stirling-PDF is vulnerable to SSRF-induced arbitrary file read. WeasyPrint redefines a set of HTML tags, including img, embed, object, and others. The references to several files inside, allow the attachment of content from any webpage or local file to a PDF. This allows the attacker to read any file on the server, including sensitive files and configuration files. All users utilizing this feature will be affected. This issue has been patched in version 0.45.0.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-46568

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Stirling-Tools

View all reports →

Affected Software

Stirling-PDF
Vulnerable Versions:
< 0.45.0

Timeline

Official Publish: May 1st, 2025
Last Modified: February 6th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)