BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Pandoc CVE-2025-51591 Exploited to Target AWS IMDS Credentials

Active Exploitation of Pandoc Vulnerability Targets AWS Metadata Service via SSRF Attacks, Mitigated by IMDSv2 and Input Sanitization

  • Security researchers discovered active attempts to exploit a vulnerability in the Linux utility Pandoc to target Amazon Web Services (AWS) Instance Metadata Service (IMDS).
  • The flaw, tracked as CVE-2025-51591, is a Server-Side Request Forgery (SSRF) with a CVSS score of 6.5, enabling attackers to use crafted HTML iframe elements to attack.
  • AWS IMDS provides temporary credentials for applications on EC2 instances, making it a valuable target for credential theft through SSRF attacks.
  • The attack attempts were unsuccessful due to the use of newer IMDSv2, which requires extra authentication steps that prevent simple SSRF-driven credential theft.
  • Experts recommend using IMDSv2, input sanitization, and principle of least privilege to reduce risk and impact of such vulnerabilities.

Cloud security firm Wiz reported in-the-wild exploitation attempts against a vulnerability in the Linux utility Pandoc, aiming to breach the Amazon Web Services (AWS) Instance Metadata Service (IMDS). These incidents began in August and lasted for several weeks, seeking to steal temporary credentials in AWS cloud environments.

- Advertisement -

The exploited vulnerability, CVE-2025-51591, allows attackers to use specially crafted HTML iframe tags to launch Server-Side Request Forgery (SSRF) attacks. According to Wiz, if successful, the flaw could allow intruders to gain access to sensitive instance metadata or temporary credentials used to interact with core AWS services.

Researchers Hila Ramati and Gili Tikochinski at Wiz explained, “If the application can reach the IMDS endpoint and is susceptible to SSRF, the attacker can harvest temporary credentials without needing any direct host access (such as RCE or path traversal).” They added that the attacks focused on injecting malicious iframes into Pandoc documents to collect data from IMDS endpoints such as /latest/meta-data/iam/info.

Past incidents show SSRF vulnerabilities can pose real threats. In early 2022, Mandiant, part of Google, reported attackers exploited SSRF flaws—including CVE-2021-21311 in the Adminer tool—to steal credentials from AWS instances using IMDS.

IMDS, specifically its older version IMDSv1, operates through a simple request-and-response model, making it an attractive target for SSRF attacks. However, the latest attack attempts failed because IMDSv2 was enabled. IMDSv2 uses session tokens and specific headers, requiring multiple authentication steps that block unauthorized access through basic SSRF techniques.

- Advertisement -

Security experts recommend addressing CVE-2025-51591 by using sanitization options in Pandoc, such as the “-f html+raw_html” or “–Sandbox” switch, which prevent loading potentially dangerous iframes. Wiz noted, “[Pandoc maintainers] decided that rendering iframes is the intended behavior and that the user is responsible to either sanitize the input or use the sandbox flags when handling user inputs.”

Further protection includes enforcing IMDSv2 across all AWS EC2 instances and assigning instance roles with only the minimum permissions required. These measures help contain risks if attackers successfully exploit SSRF flaws in third-party software running on cloud infrastructure.

Additional findings indicate threat actors have also targeted similar SSRF bugs in other cloud applications, such as ClickHouse, though security measures prevented successful breaches.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Kelp Exploit Triggers DeFi Contagion, Losses Top $293M

The Kelp liquid restaking protocol was exploited on Saturday, draining $293 million and triggering...

Rosenblatt Raises Nvidia Target to $325, Sees $1T AI Demand

NVIDIA stock outperformed the S&P 500 and its sector, climbing approximately 8% over the...

RaveDAO Denies Manipulation as Exchanges Probe Token Plunge

RaveDAO has denied responsibility for its RAVE token's extreme price volatility following allegations of...

Robinhood Soars 31% on SEC Rule Change and Crypto Rally

Robinhood (HOOD) stock surged 31% this week, making it the top performer in the...

Bitcoin Eyes $82K by April’s End Amid Volatility

Analysts predict a final push for Bitcoin towards the $78,000-$80,000 zone before a potential...

Must Read

17 Best Audiobooks On Blockchain Technology For Beginners

If you're looking to dive into the world of blockchain technology, you're in for a treat. The field is rapidly evolving and the potential...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading