PT-2026-28600 · Unknown · Stirling-Pdf

Alan951

·

Published

2026-03-26

·

Updated

2026-05-14

·

CVE-2026-34071

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Stirling-PDF versions prior to 2.8.0
Description Stirling-PDF is a locally hosted web application designed for PDF file operations. The /api/v1/convert/eml/pdf API endpoint, when used with the downloadHtml=true parameter, returns unsanitized HTML from the email body if the content type is text/html. This allows an attacker to achieve JavaScript execution by sending a malicious email to a Stirling-PDF user and having them export the email using the "Download HTML intermediate file" feature. The downloadHtml parameter is the vulnerable component in this process.
Recommendations Versions prior to 2.8.0 should be updated to version 2.8.0 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-34071
GHSA-XMHG-FV84-JGFC

Affected Products

Stirling-Pdf