CVE-2026-33437: Stirling PDF: Stored XSS in Info Summary
Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. Prior to 2.0.0, the Get Info workflow in app/core/src/main/resources/templates/security/get-info-on-pdf.html inserts untrusted PDF Title and Author metadata into the summary-text element with innerHTML, allowing a malicious PDF to execute stored cross-site scripting when a user clicks Get Info and to access browser-session data or modify page content. This issue is fixed in version 2.0.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Stirling PDFto a version that resolves this vulnerability.Fixed in 2.0.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33437?
CVE-2026-33437 has a severity rating of high with a score of 8.1.
How do I fix CVE-2026-33437?
To fix CVE-2026-33437, upgrade to Stirling PDF version 2.0.0 or later.
What vulnerability type is CVE-2026-33437 classified as?
CVE-2026-33437 is classified as a Stored Cross-Site Scripting (XSS) vulnerability.
What impact can CVE-2026-33437 have on users?
CVE-2026-33437 can allow an attacker to execute arbitrary JavaScript in the context of a user's session.
Which versions of Stirling PDF are affected by CVE-2026-33437?
CVE-2026-33437 affects all versions of Stirling PDF prior to 2.0.0.