CyberRota Analysis
AI-GeneratedBentoPDF versions 2.8.6 and earlier are vulnerable due to a flaw in the CORS proxy that allows an attacker to manipulate hostname validation, potentially redirecting requests to internal or reserved destinations. This could lead to unauthorized access to sensitive data or services, particularly for deployments lacking the PROXY_SECRET, which bypasses an important signature check. Organizations using BentoPDF, especially those with self-hosted instances, should prioritize upgrading to version 2.8.7 to mitigate this high-severity risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
BentoPDF is a client-side PDF toolkit that is self hostable. In 2.8.6 and earlier, the certificate and timestamp CORS proxy in cloudflare/cors-proxy-worker.js uses isPrivateOrReservedHost() to validate a supplied hostname separately from the DNS resolution used by fetch(targetUrl), allowing an attacker-controlled hostname to resolve to an internal or reserved destination after validation. A certificate-like path can satisfy ALLOWED_PATH_PATTERNS, and direct clients can forge the browser-oriented Origin header. Deployments without PROXY_SECRET skip the optional signature check, while the signature is an anti-abuse measure rather than a destination-security boundary. The proxy has a 10 MB response limit and can relay response bodies from reachable destinations. The advisory identifies both the official Worker deployment and self-hosted instances as impacted where the Worker execution environment can reach internal or reserved destinations. This vulnerability is fixed in 2.8.7.