PT-2026-97858 · Bentopdf · Bentopdf

CVE-2026-63630

·

Published

2026-09-24

·

Updated

2026-09-24

CVSS v3.1

3.4

Low

VectorAV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions BentoPDF versions prior to 2.8.7
Description The deserializeWorkflow() function accepts the tsaUrl control of the Timestamp node from imported JSON without performing schema or destination validation. If a user imports a crafted workflow and executes it on a PDF, the timestampPdf() function sends an RFC 3161 TimeStampReq containing the PDF's SHA-256 MessageImprint to an endpoint selected by the attacker. In default self-hosted configurations where VITE CORS PROXY URL is not set, the request bypasses ALLOWED TSA HOSTS checks and is sent directly. This allows an attacker to obtain a document digest, which can be used to confirm if a document matches a known file or to correlate the same document across different users without accessing the actual content.
Recommendations Update to version 2.8.7.

Exploit

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63630
GHSA-CX8X-7RRR-R9X8

Affected Products

Bentopdf