CVE-2026-33436

Source
https://cve.org/CVERecord?id=CVE-2026-33436
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-33436.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-33436
Aliases
  • GHSA-q5j3-4m5w-wp75
Published
2026-04-17T20:29:43.262Z
Modified
2026-07-15T01:49:08.655124975Z
Severity
  • 3.1 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Stirling-PDF: Reflected XSS through crafted filename in file upload functionality
Details

Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. In versions prior to 2.0.0, file upload endpoints render user-supplied filenames directly into HTML using unsafe methods like innerHTML without sanitization. An attacker can craft a file with a malicious filename containing JavaScript that executes in the uploading user's browser context, resulting in reflected XSS. The issue affects numerous upload endpoints across the application. The issue has been fixed in version 2.0.0.

Database specific
{
    "cwe_ids": [
        "CWE-116",
        "CWE-20",
        "CWE-79"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33436.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/stirling-tools/stirling-pdf

Affected ranges

Type
GIT
Repo
https://github.com/stirling-tools/stirling-pdf
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "cpe": "cpe:2.3:a:stirlingpdf:stirling_pdf:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2.0.0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "CPE_RANGE"
    ]
}

Affected versions

0.*
0.13.0
stirling-pdf-chart-1.*
stirling-pdf-chart-1.0.1
v0.*
v0.10.0
v0.10.1
v0.10.2
v0.10.3
v0.12.0
v0.12.1
v0.12.2
v0.13.0
v0.13.1
v0.14.0
v0.14.1
v0.14.2
v0.14.3
v0.14.4
v0.14.5
v0.15.0
v0.15.1
v0.16.0
v0.16.1
v0.17.0
v0.17.1
v0.17.2
v0.18.0
v0.18.1
v0.19.0
v0.19.1
v0.20.0
v0.20.1
v0.20.2
v0.21.0
v0.22.0
v0.22.1
v0.22.2
v0.22.3
v0.22.4
v0.22.5
v0.22.6
v0.22.7
v0.22.8
v0.23.0
v0.23.1
v0.24.0
v0.24.1
v0.24.2
v0.24.3
v0.24.4
v0.24.5
v0.24.6
v0.25.0
v0.25.1
v0.25.2
v0.25.3
v0.26.0
v0.26.1
v0.27.0
v0.28.0
v0.28.1
v0.28.2
v0.28.3
v0.29.0
v0.3.0
v0.3.2
v0.3.3
v0.3.4
v0.30.0
v0.30.1
v0.31.0
v0.31.1
v0.32.0
v0.33.0
v0.33.1
v0.34.0
v0.35.0
v0.35.1
v0.36.0
v0.36.1
v0.36.2
v0.36.3
v0.36.4
v0.36.5
v0.36.6
v0.37.0
v0.37.1
v0.38.0
v0.39.0
v0.4.0
v0.4.2
v0.4.3
v0.4.4
v0.4.5
v0.4.6
v0.4.7
v0.4.8
v0.40.0
v0.40.1
v0.40.2
v0.41.0
v0.42.0
v0.43.0
v0.43.1
v0.43.2
v0.44.0
v0.44.1
v0.44.2
v0.44.3
v0.45.0
v0.45.1
v0.45.2
v0.45.3
v0.45.4
v0.45.5
v0.45.6
v0.46.0
v0.46.1
v0.5.0
v0.6.0
v0.7.0
v0.8.0
v0.8.1
v0.8.2
v0.8.3
v0.9.0
v0.9.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-33436.json"