CVE-2026-63630

CVE-2026-63630 published: BentoPDF is a client-side PDF toolkit that is self hostable. In 2.8.6 and earlier, deserializeWorkflow() accepts the Timestamp node's tsaUrl control from imported JSON without schema or destination validation. When a user imports the crafted workflow and ru...

View full NVD advisory → ← Back to CVE watch