Attackers have exploited a server-side request forgery (SSRF) vulnerability in the Pandoc Linux utility, identified as CVE-2025-51591, to target the Amazon Web Services (AWS) Instance Metadata Service (IMDS) and steal EC2 IAM credentials. The flaw, which has a CVSS score of 6.5, allows threat actors to inject specially crafted HTML iframe elements into Pandoc, enabling them to direct requests to the IMDS endpoint. By leveraging this SSRF vulnerability, attackers can harvest temporary AWS credentials from EC2 instances without requiring direct host access, such as remote code execution or path traversal. The IMDS is a critical AWS component that provides metadata and temporary credentials to applications running on EC2 instances, facilitating secure interactions with other AWS services like S3, RDS, and DynamoDB. The exploitation method involves submitting HTML documents with malicious iframe elements, which, if processed by a vulnerable Pandoc instance on an EC2 host, can access sensitive metadata paths and extract credentials. Security researchers from Wiz highlighted that enforcing IMDSv2, which requires session-based authentication, can effectively block such attacks, as was observed in incidents where IMDSv2 was enabled. Organizations are advised to mitigate this risk by using Pandoc's '-f html+raw_html' or '--sandbox' options and by ensuring IMDSv2 is enforced across all EC2 environments. The attacks underscore the broader risk posed by SSRF vulnerabilities in cloud environments, as they can lead to severe consequences such as network reconnaissance and cloud credential compromise. Resecurity researchers have warned that SSRF flaws, when combined with access to IMDS, can have far-reaching impacts on cloud security. The incident demonstrates that attackers are actively searching for SSRF vulnerabilities in web applications running on EC2 instances to gain unauthorized access to AWS resources. The exploitation of CVE-2025-51591 is not merely theoretical; it has been observed in the wild, with real-world attempts to compromise cloud infrastructure. The incident also highlights the importance of secure application design and the need for defense-in-depth strategies in cloud environments. Security teams are urged to review their use of Pandoc and similar utilities, especially in cloud-hosted environments, to ensure they are not inadvertently exposing sensitive metadata endpoints. The case further illustrates the evolving tactics of threat actors targeting cloud infrastructure through application-layer vulnerabilities. Cloud providers and customers alike must remain vigilant and proactive in patching and securing their environments against such emerging threats. The incident serves as a reminder that even medium-severity vulnerabilities can have significant impact when exploited in the right context. Finally, the coordinated disclosure and analysis by security firms like Wiz have been instrumental in raising awareness and driving mitigation efforts for this vulnerability.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Security reporting detailed that exploitation of CVE-2025-51591 could be blocked by enforcing AWS IMDSv2 and by using safer Pandoc options. The disclosure highlighted the broader risks of SSRF, including cloud credential theft and internal network reconnaissance.
Threat actors actively exploited the Pandoc server-side request forgery vulnerability CVE-2025-51591 by submitting crafted HTML documents with iframes targeting the AWS Instance Metadata Service. The activity was aimed at retrieving EC2 IAM temporary credentials without requiring direct access to the host.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.