SEPTEMBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-41580

MEDIUM · CVSS 6.1 EPSS 0.23% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-15 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

The Stirling-PDF web application prior to version 2.0.0 is vulnerable due to improper HTML encoding and sanitization of PDF Title and Author metadata fields, which can lead to the execution of malicious JavaScript in users' browsers. This vulnerability poses a medium risk as it could allow attackers to execute arbitrary scripts, potentially compromising user data or session information. Organizations using Stirling-PDF should prioritize upgrading to version 2.0.0 to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-41580
Severity
MEDIUM
CVSS
6.1
EPSS
0.23%
Java

Original NVD Description

Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. Prior to 2.0.0, Stirling-PDF's /get-info-on-pdf endpoint rendered PDF Title and Author metadata fields without proper HTML encoding or sanitization, allowing a crafted PDF to execute attacker-controlled JavaScript in the browser of a user who views the resulting page. This issue is fixed in version 2.0.0.

Related CVEs

Other vulnerabilities affecting the same vendor(s)