What is CVE-2026-33437?
This vulnerability in Stirling-PDF arises from unsanitized PDF Title and Author metadata being inserted into the page via innerHTML in the Get Info workflow, leading to potential XSS (Cross-Site Scripting) attacks through a crafted PDF file. Users are advised to upgrade to version 2.0.0 to mitigate the issue.
Azərbaycanca: Stirling-PDF tətbiqində aşkar edilmiş bu boşluq PDF fayllarının Title və Author metadata sahələrinin sanitizasiya olunmadan innerHTML ilə səhifəyə daxil edilməsi nəticəsində yaranır. Bu, təcavüzkara xüsusi hazırlanmış PDF faylı vasitəsilə XSS (Cross-Site Scripting) hücumu həyata keçirməyə imkan verir. İstifadəçilər tətbiqi 2.0.0 versiyasına yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which metadata fields in Stirling-PDF are exploited in CVE-2026-33437?
This vulnerability arises from improper sanitization of the PDF Title and Author metadata fields.
To which version should users upgrade to fix CVE-2026-33437?
Users are advised to upgrade Stirling-PDF to version 2.0.0 to mitigate the issue.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.