When converting HTML and DOCX files to PDF using Spire.Officefor.NETStandard, the library performs unauthorized outbound HTTP requests to external URLs referenced inside the document (e.g., images loaded via <img src="…">).
This behavior introduces a critical security risk:
- - It enables Reflected Cross-Site-Scripting (XSS) / Injection attacks, aligned with OWASP TOP 10 – A03:2021 Injection.
- It allows the application to act as an unintended proxy toward arbitrary hosts.
- It may lead to data leakage, server IP exposure, or SSRF-like effects.
This occurs silently and automatically when loading the document—no explicit configuration triggers this behavior.
Environment
- - Application: ASP.NET Core 8
- Library: Spire.Officefor.NETStandard
Conversion code:
- Code: Select all
using FileStream fs = File.OpenRead("path");
using Document document = new();
document.LoadFromStream(fs, FileFormat.Auto);
document.SaveToFile("output.pdf", FileFormat.PDF);
Impact
- - Potential data exfiltration via external HTTP requests.
- Possible injection attack vector, where malicious users craft HTML/DOCX documents containing harmful URLs.
- Undocumented and uncontrollable behavior, making mitigation impossible on the application side.
- Violation of internal security policies (unexpected outbound traffic).
Steps to Reproduce
- 1. Create a minimal HTML file:
- Code: Select all
<!html>
<body>
<img src="URL of an externally hosted image">
</body>- Code: Select all
using FileStream fs = File.OpenRead("file.html");
using Document document = new();
document.LoadFromStream(fs, FileFormat.Auto);
document.SaveToFile("output.pdf", Spire.Doc.FileFormat.PDF);
2. Convert the file to PDF using Spire:
3. Monitor the traffic using a tool such as Wireshark.
4. Observe that the library performs a direct HTTP request to the external URL to retrieve the image.
Requested Actions
- 1. Confirm whether this behavior is intended.
2. Clarify if there is any flag / option / configuration to:
- - completely disable remote resource loading;
- force usage of embedded or local resources only;
- automatically replace remote resources with placeholders;
- intercept or block outbound HTTP requests performed by the library.
- - provide a patch, hotfix, or updated version that removes or makes this behavior configurable.
- - known vulnerabilities,
- recommended security best practices,
- or safer alternatives.
Best regards,
Alessandro