Cross-Site Scripting Vulnerability in BentoPDF Toolkit by Alam
CVE-2026-41653

7HIGH

Key Information:

Vendor

Alam00000

Status
Vendor
CVE Published:
7 May 2026

What is CVE-2026-41653?

BentoPDF, a self-hostable client-side PDF toolkit, was found to have a cross-site scripting vulnerability prior to version 2.8.3. This security flaw allows attackers to execute arbitrary JavaScript in specific scenarios involving the Markdown to PDF Tool. Users are advised to upgrade to version 2.8.3 or later to mitigate this issue. More information can be found on the project's GitHub advisory and release page.

Affected Version(s)

bentopdf < 2.8.3

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.