CVE-2026-47664: CWE-20: Improper Input Validation in aehrc pathling
Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling Server, the `$import-pnp` operation in Pathling Server accepts a caller-supplied `exportUrl` and uses it as the remote FHIR Bulk Export endpoint without constraining it to a trusted source. When PNP credentials are configured, Pathling builds a credentialed bulk-export client targeting the caller-chosen host, downloads manifest-selected files, and then reclassifies those staged files as trusted local `file://` imports - bypassing the configured `allowableSources` allowlist that protects the ordinary `$import` operation. This is fixed in Pathling Server 2.0.0. As a workaround, disable the `$import-pnp` operation (`pathling.operations.importPnpEnabled=false`) or do not configure PNP credentials.
AI Analysis
Technical Summary
Pathling Server versions before 2.0.0 contain an improper input validation vulnerability in the $import-pnp operation. This operation accepts a caller-supplied exportUrl used as a remote FHIR Bulk Export endpoint without restricting it to trusted sources. When PNP credentials are configured, Pathling creates a credentialed bulk-export client targeting the caller-chosen host, downloads manifest-selected files, and reclassifies them as trusted local file:// imports. This process bypasses the allowableSources allowlist that normally protects the $import operation, potentially allowing unauthorized import of data from arbitrary remote endpoints. The vulnerability is addressed in Pathling Server 2.0.0. Workarounds include disabling the $import-pnp operation or not configuring PNP credentials.
Potential Impact
An attacker able to invoke the $import-pnp operation can specify an arbitrary exportUrl, causing Pathling Server to download and trust data from an untrusted remote FHIR Bulk Export endpoint. This bypasses the configured allowableSources protection, potentially leading to unauthorized data import and trust boundary violations within health data analytics workflows. The CVSS 4.0 score of 8.6 reflects high impact due to network attack vector, low attack complexity, no privileges required, no user interaction, and high impact on confidentiality and integrity.
Mitigation Recommendations
A fix is available in Pathling Server version 2.0.0. Until upgrading, users should disable the $import-pnp operation by setting pathling.operations.importPnpEnabled=false or avoid configuring PNP credentials to prevent exploitation of this vulnerability.
CVE-2026-47664: CWE-20: Improper Input Validation in aehrc pathling
Description
Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling Server, the `$import-pnp` operation in Pathling Server accepts a caller-supplied `exportUrl` and uses it as the remote FHIR Bulk Export endpoint without constraining it to a trusted source. When PNP credentials are configured, Pathling builds a credentialed bulk-export client targeting the caller-chosen host, downloads manifest-selected files, and then reclassifies those staged files as trusted local `file://` imports - bypassing the configured `allowableSources` allowlist that protects the ordinary `$import` operation. This is fixed in Pathling Server 2.0.0. As a workaround, disable the `$import-pnp` operation (`pathling.operations.importPnpEnabled=false`) or do not configure PNP credentials.
CVSS v4.0
Score 8.6high
Affected software
aehrc
pathling
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Pathling Server versions before 2.0.0 contain an improper input validation vulnerability in the $import-pnp operation. This operation accepts a caller-supplied exportUrl used as a remote FHIR Bulk Export endpoint without restricting it to trusted sources. When PNP credentials are configured, Pathling creates a credentialed bulk-export client targeting the caller-chosen host, downloads manifest-selected files, and reclassifies them as trusted local file:// imports. This process bypasses the allowableSources allowlist that normally protects the $import operation, potentially allowing unauthorized import of data from arbitrary remote endpoints. The vulnerability is addressed in Pathling Server 2.0.0. Workarounds include disabling the $import-pnp operation or not configuring PNP credentials.
Potential Impact
An attacker able to invoke the $import-pnp operation can specify an arbitrary exportUrl, causing Pathling Server to download and trust data from an untrusted remote FHIR Bulk Export endpoint. This bypasses the configured allowableSources protection, potentially leading to unauthorized data import and trust boundary violations within health data analytics workflows. The CVSS 4.0 score of 8.6 reflects high impact due to network attack vector, low attack complexity, no privileges required, no user interaction, and high impact on confidentiality and integrity.
Mitigation Recommendations
A fix is available in Pathling Server version 2.0.0. Until upgrading, users should disable the $import-pnp operation by setting pathling.operations.importPnpEnabled=false or avoid configuring PNP credentials to prevent exploitation of this vulnerability.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-19T21:10:38.797Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a76468dbf8831d53924fd8e
Added to database: 08/07/2026, 20:56:45 UTC
Last enriched: 08/15/2026, 15:33:44 UTC
Last updated: 09/22/2026, 01:52:43 UTC
Views: 60
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.