PT-2026-97858 · Bentopdf · Bentopdf
CVE-2026-63630
·
Published
2026-09-24
·
Updated
2026-09-24
CVSS v3.1
3.4
Low
| Vector | AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
BentoPDF versions prior to 2.8.7
Description
The
deserializeWorkflow() function accepts the tsaUrl control of the Timestamp node from imported JSON without performing schema or destination validation. If a user imports a crafted workflow and executes it on a PDF, the timestampPdf() function sends an RFC 3161 TimeStampReq containing the PDF's SHA-256 MessageImprint to an endpoint selected by the attacker. In default self-hosted configurations where VITE CORS PROXY URL is not set, the request bypasses ALLOWED TSA HOSTS checks and is sent directly. This allows an attacker to obtain a document digest, which can be used to confirm if a document matches a known file or to correlate the same document across different users without accessing the actual content.Recommendations
Update to version 2.8.7.
Exploit
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bentopdf