All 3 CVE vulnerabilities found in bentopdf, with AI-generated Chinese analysis, references, and POCs.
Vendor: alam00000
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-63630 | BentoPDF: Workflow Import Allows Unvalidated TSA URL Leading to PDF Hash Exfiltration via RFC 3161 Requests CWE-502 | 3.4 | Low | 2026-09-24 |
| CVE-2026-77581 | BentoPDF: SSRF in cors-proxy-worker.js via DNS-based hostname allowlist bypass CWE-918 | 8.6 | High | 2026-09-24 |
| CVE-2026-41653 | BentoPDF: Stored XSS via Markdown Editor Leading to Persistent File Exfiltration CWE-79 | 6.1AI | Medium AI | 2026-05-07 |
All 3 known CVE vulnerabilities affecting bentopdf with full Chinese analysis, references, and POCs where available.