PT-2026-38546 · Bentopdf · Bentopdf
Astaruf
·
Published
2026-05-07
·
Updated
2026-05-08
·
CVE-2026-41653
CVSS v4.0
7.0
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
BentoPDF versions prior to 2.8.3
Description
BentoPDF is a self-hostable client-side PDF toolkit. A cross-site scripting issue exists in the Markdown to PDF Tool, which allows an attacker to execute arbitrary JavaScript under certain circumstances.
Recommendations
Update to version 2.8.3.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bentopdf