Description

A Local File Inclusion (LFI) and a Server-Side Request Forgery (SSRF) vulnerability was found in the InsertFromHtmlString() function of the Apryse HTML2PDF SDK thru 11.6.0. These vulnerabilities could allow an attacker to read local files on the server or make arbitrary HTTP requests to internal or external services. Both vulnerabilities could lead to the disclosure of sensitive data or potential system takeover.

INFO

Published Date :

2026-01-22T00:00:00.000Z

Last Modified :

2026-01-26T18:55:29.116Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2025-56589 vulnerability.

Vendors Products
Apryse
  • Html2pdf
  • Html2pdf Sdk
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-56589.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact