PatchSiren

Stirling-Tools CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Stirling-Tools CVE published 2026-08-17

CVE-2026-57485

CVE-2026-57485 is a high-severity vulnerability in Stirling-PDF, a locally hosted web application for PDF file operations. An authenticated user can exploit this issue to retrieve an API key, impersonate an internal service account, bypass rate limits, and access internal endpoints. The vulnerability is fixed in version 2.9.0. This issue allows for potential unauthorized access and data breaches, emphasiz [truncated]

HIGH Stirling-Tools CVE published 2026-08-05

CVE-2026-71270

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T13:24:51.327Z and has not been modified since then. The vulnerability affects Stirling-PDF's POST /api/v1/convert/url/pdf endpoint, which lacks CustomHtmlSanitizer/SsrfProtectionService SSRF protections. This allows potential SSRF attacks, enabling an attacker to cause the server to retrieve clou [truncated]

MEDIUM Stirling-Tools CVE published 2026-07-15

CVE-2026-41580

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-15T16:16:45.223Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability affects Stirling-PDF, a locally hosted web application for PDF operations, allowing crafted PDFs to execute attacker-controlled JavaScript in users' browsers prior to version 2.0.0 due to i [truncated]