A Server-Side Request Forgery (SSRF) in JGM Pandoc v3.6.4 allows attackers to gain access to and compromise the whole infrastructure via injecting a crafted iframe.
https://thehackernews.com/2025/09/hackers-exploit-pandoc-cve-2025-51591.html
https://www.wiz.io/blog/imds-anomaly-hunting-zero-day
https://github.com/jgm/pandoc/issues/10682
https://github.com/jgm/pandoc/commit/67edf7ce7cd3563a180ae44bd122b012e22364f8
https://github.com/RealestName/Vulnerability-Research/tree/main/CVE-2025-51591