CVE 3.1 LOW

Stirling-PDF: Reflected XSS through crafted filename in file upload functionality_CVE-2026-33436

3.1 / 10
LOW
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N

Description

Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. In versions prior to 2.0.0, file upload endpoints render user-supplied filenames directly into HTML using unsafe methods like innerHTML without sanitization. An attacker can craft a file with a malicious filename containing JavaScript that executes in the uploading user's browser context, resulting in reflected XSS. The issue affects numerous upload endpoints across the application. The issue has been fixed in version 2.0.0.

Basic Information

ID CVE-2026-33436
Source GitHub_M
Published Apr 17, 2026 at 20:29

Affected Product

Vendor Stirling-Tools
Product Stirling-PDF
Version < 2.0.0
Affected Versions Stirling-Tools Stirling-PDF < 2.0.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.