๐Ÿ” CVE Alert

CVE-2026-81659

UNKNOWN 0.0

Flowintel Note PDF Export Allows Arbitrary Local File Read via Pandoc/XeLaTeX Processing

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Affected versions of Flowintel allow attacker-controlled note content to be processed by Pandoc and XeLaTeX during PDF export in a way that can cause local files on the Flowintel server to be read and incorporated into the generated export.

CWE CWE-22
Vendor flowintel
Product flowintel
Published Aug 27, 2026
Stay Ahead of the Next One

Get instant alerts for flowintel flowintel

Be the first to know when new unknown vulnerabilities affecting flowintel flowintel are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

flowintel / flowintel
0 โ‰ค 3.3.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/flowintel/flowintel/commit/16f618fa36a72c4c5ca3ff0abf7dd67455318ef1 github.com: https://github.com/flowintel/flowintel/commit/2ba9700a5473223639575050bda607f498add7c6

Credits

Jeroen Pinoy David Cruciani