Known vulnerabilities in pandoc

Vendor: jgm
Software: pandoc
Software CPE: cpe:2.3:a:jgm:pandoc:*:*:*:*:*:*:*:*
Total vulnerabilities: 2
Public exploits: 1
Known exploited (KEV): 1
Highest CVSSv4 Score: 8.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting pandoc pandoc is affected by 2 known vulnerabilities: 1 high, 1 medium Critical High Medium Low

Vulnerabilities (2)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU116079 - Server-Side Request Forgery (SSRF)
CVE-2025-51591
CWE-918 High
Available
Exploited
3.6.4 24.09.2025 SB2025092440
SB2025092441
SB2025092949
#VU127460 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2023-35936
CWE-22 Medium
No
No
3.1.4 04.07.2023 SB2023070449