Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-63630— BentoPDF: Workflow Import Allows Unvalidated TSA URL Leading to PDF Hash Exfiltration via RFC 3161 Requests

Quick assessment

Affected
alam00000 bentopdf
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

BentoPDF 是一个客户端 PDF 工具包,支持自我托管。在版本 2.8.6 及更早版本中, 函数在处理从导入的 JSON 文件时,未对 Timestamp 节点的 控制字段进行模式验证或目标地址验证。当用户导入构造的恶意工作流并将其应用于某个 PDF 时, 函数会向攻击者指定的端点发送一个包含该 PDF SHA-256 消息摘要(MessageImprint)的 RFC 3161 TimeStampReq 请求。由于默认的自托管配置未设置环境变量 ,该请求绕过了代理服务器的 安全限制,直接被发送出去。泄露的摘

CVSS 3.4 · Low EPSS 0.31% · P22

Affected Version Matrix 1

VendorProduct Version RangeStatus
alam00000 bentopdf < 2.8.7 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-63630

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
BentoPDF: Workflow Import Allows Unvalidated TSA URL Leading to PDF Hash Exfiltration via RFC 3161 Requests
Source: CVE Program / CVE List V5
Vulnerability Description
BentoPDF is a client-side PDF toolkit that is self hostable. In 2.8.6 and earlier, deserializeWorkflow() accepts the Timestamp node's tsaUrl control from imported JSON without schema or destination validation. When a user imports the crafted workflow and runs it against a PDF, timestampPdf() sends an RFC 3161 TimeStampReq containing the PDF's SHA-256 MessageImprint to the attacker-selected endpoint. The default self-hosted configuration does not set VITE_CORS_PROXY_URL, so the request bypasses the proxy's ALLOWED_TSA_HOSTS checks and is sent directly. The disclosed digest can confirm that a document matches a known file and can correlate the same document across users without revealing its contents. This vulnerability is fixed in 2.8.7.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
可信数据的反序列化
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
alam00000 bentopdf < 2.8.7 -

II. Public POCs for CVE-2026-63630

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-63630

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-63630 (2)

Vendor Advisories for CVE-2026-63630 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-63630

No comments yet


Leave a comment