Nixpkgs security tracker

Login with GitHub

Details of issue NIXPKGS-2026-1446

NIXPKGS-2026-1446
published on
updated 8 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
BentoPDF: Stored XSS via Markdown Editor Leading to Persistent File Exfiltration

BentoPDF is a client-side PDF toolkit that is self hostable. Prior to version 2.8.3, a cross-site scripting vulnerability was identified in BentoPD. An attacker may be able to execute arbitrary JavaScript in certain circumstances in Markdown to PDF Tool. This issue has been patched in version 2.8.3.

Affected products

bentopdf
  • ==< 2.8.3

Matching in nixpkgs

Package maintainers