A Server-Side Request Forgery (SSRF) in JGM Pandoc v3.6.4 allows attackers to gain access to and compromise the whole infrastructure via injecting a crafted iframe.
https://thehackernews.com/2025/09/hackers-exploit-pandoc-cve-2025-51591.html
https://github.com/RealestName/Vulnerability-Research/tree/main/CVE-2025-51591