PT-2026-26592 · Unknown · Stirling-Pdf
Sy460129
·
Publicado
2026-03-20
·
Atualizado
2026-03-22
·
CVE-2026-27625
CVSS v3.1
8.1
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Stirling-PDF versions prior to 2.5.2
Description
Stirling-PDF is a locally hosted web application used for PDF file operations. Versions prior to 2.5.2 have an issue where the
/api/v1/convert/markdown/pdf endpoint does not properly validate paths when extracting entries from user-supplied ZIP files. This allows an authenticated user to write files outside the intended temporary directory, resulting in arbitrary file write with the privileges of the stirlingpdfuser process. This can lead to overwriting writable files and compromising data integrity. The vulnerable parameter is the ZIP file provided to the /api/v1/convert/markdown/pdf endpoint.Recommendations
Update Stirling-PDF to version 2.5.2 or later.
Exploit
Correção
Relative Path Traversal
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Stirling-Pdf