Executive brief
Stirling-PDF is a self-hosted web application used for managing and editing PDF documents. A security flaw in the application's file upload system allows an attacker to execute malicious scripts in a user's browser if the user is tricked into uploading a file with a specially crafted name. This could lead to the theft of sensitive session information, such as cookies, or unauthorized actions performed on behalf of the user.
Technical details
A reflected Cross-Site Scripting (XSS) vulnerability exists in Stirling-PDF versions prior to 2.0.0. The root cause is the use of unsafe JavaScript methods like 'innerHTML' to display uploaded filenames in the web interface without prior sanitization or output encoding. An attacker can exploit this by inducing a user to upload a file with a malicious filename containing JavaScript (e.g., <img src=x onerror=alert(1)>.pdf). Upon upload, the script executes within the context of the victim's browser session. This affects numerous endpoints including /merge-pdfs, /split-pdfs, and /convert-to-pdf. The issue is addressed in version 2.0.0 by implementing proper input validation and output escaping.
Affected products
- Stirling-Tools Stirling-PDF < 2.0.0
Timeline
- 2026-04-17: disclosed
- 2026-04-17: advisory
- 2026-04-17: patched: Fixed in version 2.0.0