Validated Containment Architectures are here. →Explore

Executive Summary

In September 2025, threat actors exploited a newly disclosed Server-Side Request Forgery (SSRF) vulnerability in the open-source Linux utility Pandoc (CVE-2025-51591), targeting Amazon Web Services (AWS) cloud environments. The attackers leveraged the flaw to send unauthorized requests to the AWS Instance Metadata Service (IMDS), allowing them to obtain EC2 role credentials and elevate cloud permissions. Security researchers, including Wiz, observed active exploitation in the wild, leading to unauthorized access and potential data exfiltration from affected AWS infrastructure. Organizations relying on Pandoc as part of their cloud automation workflows face heightened risk of credential compromise and lateral movement across accounts.

This incident underscores a fast-evolving cloud threat landscape, where attackers exploit supply-chain and open-source vulnerabilities to traverse trusted infrastructure and target sensitive identity and metadata services. The rapid weaponization of CVE-2025-51591 mirrors the broader trend of SSRF attacks on cloud metadata, driving urgent calls for proactive detection, segmentation, and credential management in multi-cloud environments.

Why This Matters Now

Cloud supply chain and open-source component vulnerabilities are now being rapidly weaponized by attackers to breach cloud-native environments, access sensitive IMDS endpoints, and steal dynamic IAM credentials. As organizations expand automation and rely on tools like Pandoc, the window between vulnerability disclosure and exploitation is shrinking—making swift detection, zero trust segmentation, and robust egress policies urgently necessary to block credential theft and prevent widespread compromise.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The incident highlights weaknesses in supply chain controls, east-west segmentation, credential safeguards, and insufficient egress filtering around metadata endpoints—impacting PCI, HIPAA, and NIST requirements.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Network segmentation, east-west traffic controls, egress policy enforcement, and threat detection provided by CNSF and zero trust frameworks would have significantly limited the attacker's ability to exploit, move laterally, or exfiltrate data at multiple points in the kill chain.

Initial Compromise

Control: Inline IPS (Suricata)

Mitigation: Attempted SSRF exploit detected and blocked inline.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Access to metadata endpoints restricted by microsegmentation.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Lateral movement between services detected and blocked.

Command & Control

Control: Threat Detection & Anomaly Response

Mitigation: Anomalous or unauthorized outbound communication detected and alerted.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Unauthorized data exfiltration attempt blocked at the network edge.

Impact (Mitigations)

Unusual resource or identity actions detected across cloud environments.

Impact at a Glance

Affected Business Functions

  • Cloud Infrastructure Management
  • Data Security
Operational Disruption

Estimated downtime: 3 days

Financial Impact

Estimated loss: $50,000

Data Exposure

Potential unauthorized access to AWS IAM credentials, leading to possible data breaches and unauthorized access to cloud resources.

Recommended Actions

  • Enforce strict zero trust segmentation to prevent unauthorized workload-to-workload and metadata endpoint access.
  • Deploy inline intrusion prevention to block exploitation attempts of known vulnerabilities like Pandoc SSRF (CVE-2025-51591).
  • Implement robust egress control policies to restrict outbound traffic and prevent credential exfiltration.
  • Continuously monitor east-west and egress flows for signs of lateral movement, C2, and data leak attempts.
  • Centralize multicloud visibility for unified policy enforcement, alerting, and rapid incident response across all environments.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image