CVE-2026-57485 is a high-severity vulnerability in Stirling-PDF, a locally hosted web application for PDF file operations. An authenticated user can exploit this issue to retrieve an API key, impersonate an internal service account, bypass rate limits, and access internal endpoints. The vulnerability is fixed in version 2.9.0. This issue allows for potential unauthorized access and data breaches, emphasiz [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T13:24:51.327Z and has not been modified since then. The vulnerability affects Stirling-PDF's POST /api/v1/convert/url/pdf endpoint, which lacks CustomHtmlSanitizer/SsrfProtectionService SSRF protections. This allows potential SSRF attacks, enabling an attacker to cause the server to retrieve clou [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-15T16:16:45.223Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability affects Stirling-PDF, a locally hosted web application for PDF operations, allowing crafted PDFs to execute attacker-controlled JavaScript in users' browsers prior to version 2.0.0 due to i [truncated]