Impact
Stirling‑PDF is a locally hosted web application that processes PDF files. In versions prior to 2.0.0, its /get‑info‑on‑pdf endpoint returned the PDF Title and Author metadata without proper HTML encoding or sanitization, allowing an attacker to embed malicious JavaScript. When a user opens a crafted PDF and views the resulting page, the browser executes the script, leading to reflected XSS.
Affected Systems
Stirling‑Tools Stirling‑PDF releases prior to version 2.0.0 are affected; the vulnerability is fixed starting in 2.0.0.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity, while the EPSS score of less than 1% signals a low exploitation probability in the current threat landscape. The issue is not listed in the CISA KEV catalog. Exploitation requires an attacker to supply a crafted PDF that a user opens on the local web interface, making the risk primarily confined to users who interact with the /get‑info‑on‑pdf endpoint on a compromised or maliciously constructed PDF file. With no widespread active exploitation reported, the immediate threat remains limited but non‑negligible for exposed or shared installations.
OpenCVE Enrichment