๐Ÿ” CVE Alert

CVE-2026-63630

LOW 3.4

BentoPDF: Workflow Import Allows Unvalidated TSA URL Leading to PDF Hash Exfiltration via RFC 3161 Requests

CVSS Score
3.4
EPSS Score
0.0%
EPSS Percentile
0th

BentoPDF is a client-side PDF toolkit that is self hostable. In 2.8.6 and earlier, deserializeWorkflow() accepts the Timestamp node's tsaUrl control from imported JSON without schema or destination validation. When a user imports the crafted workflow and runs it against a PDF, timestampPdf() sends an RFC 3161 TimeStampReq containing the PDF's SHA-256 MessageImprint to the attacker-selected endpoint. The default self-hosted configuration does not set VITE_CORS_PROXY_URL, so the request bypasses the proxy's ALLOWED_TSA_HOSTS checks and is sent directly. The disclosed digest can confirm that a document matches a known file and can correlate the same document across users without revealing its contents. This vulnerability is fixed in 2.8.7.

CWE CWE-502 CWE-201
Vendor alam00000
Product bentopdf
Published Sep 24, 2026
Stay Ahead of the Next One

Get instant alerts for alam00000 bentopdf

Be the first to know when new low vulnerabilities affecting alam00000 bentopdf are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

alam00000 / bentopdf
< 2.8.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/alam00000/bentopdf/security/advisories/GHSA-cx8x-7rrr-r9x8 github.com: https://github.com/alam00000/bentopdf/commit/b21f602cca972320bfffbf72e37df535313a6e48 github.com: https://github.com/alam00000/bentopdf/releases/tag/v2.8.7