Stirling-PDF < 1.1.0 contains a server side request forgery caused by bypassing the sanitizer in the /api/v1/convert/html/pdf endpoint when processing HTML to PDF conversion, letting attackers perform SSRF, exploit requires local access.
id: CVE-2025-55150
info:
name: Stirling-PDF < 1.1.0 - Server-Side Request Forgery
author: WeQi
...