CVE-2024-33864: Linqi

Medium severity, CVSS 5.9. EPSS: 0.5% chance of exploitation in the next 30 days.

An issue was discovered in linqi before 1.4.0.1 on Windows. There is SSRF via Document template generation; i.e., via remote images in process creation, file inclusion, and PDF document generation via malicious JavaScript.

Affected products

  • Linqi Linqi: before 1.4.0.1 (fixed in 1.4.0.1)

Published 2024-05-14. Last modified 2026-06-17.