CVE-2025-56589 Details
Description
A Local File Inclusion (LFI) and a Server-Side Request Forgery (SSRF) vulnerability was found in the InsertFromHtmlString() function of the Apryse HTML2PDF SDK thru 11.6.0. These vulnerabilities could allow an attacker to read local files on the server or make arbitrary HTTP requests to internal or external services. Both vulnerabilities could lead to the disclosure of sensitive data or potential system takeover.
A Local File Inclusion (LFI) and Server-Side Request Forgery (SSRF) vulnerability exist in the Apryse HTML2PDF SDK, affecting versions through 11.6.0. The issue arises in the InsertFromHtmlString() function, where an attacker could exploit the vulnerability to read local files on the server or make arbitrary HTTP requests to internal or external services. This could lead to the disclosure of sensitive data or potential system takeover.
The vendor has not acknowledged or addressed the vulnerability. However, it is recommended to sanitize any data sent to the PDF conversion functions to prevent the interpretation of malicious code or tags. Applications displaying HTML should use a trusted HTML sanitizer and apply output encoding where appropriate.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.stratascale.com/resource/apryse-server-module-ssrf-lfi/ | CISA-ADP | ExploitThird Party Advisory |
| https://www.stratascale.com/resource/apryse-server-module-ssrf-lfi/ | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| apryse html2pdf | <= 11.7.0 11.10.0 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 5, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 2, 2026 | Initial Analysis | [email protected] |
| Jan 26, 2026 | CVE Modified | CISA-ADP |
| Jan 22, 2026 | New CVE Received | [email protected] |