CVE-2026-34071 identifies a Cross-Site Scripting (XSS) vulnerability in Stirling-PDF version 2.7.3, specifically within the /api/v1/convert/eml/pdf endpoint when exporting emails with the "Download HTML intermediate file" option. This medium-severity vulnerability (CVSS 6.1) allows an unauthenticated attacker to achieve JavaScript execution in a user's browser by sending a malicious email, requiring user interaction to trigger the exploit. The potential impact includes low confidentiality and integrity, though its EPSS score of 0.000360000 indicates a very low likelihood of exploitation. There is currently no evidence of active exploitation, nor is public exploit code or significant community discussion available for this flaw, which is resolved in Stirling-PDF version 2.8.0.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.7.3CPE matchmatch criteria | cpe:2.3:a:stirling:stirling_pdf:2.7.3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.