Inject strings into PDF Info dictionary fields Related CVEs â
Embed raw XMP XML metadata for XXE/SSRF testing XXE CVEs â
PDF JavaScript via OpenAction (runs in viewer sandbox) CVEs â
Append content after %%EOF for file-type confusion CVEs â
Add clickable links with /URI actions CVEs â
Hide files inside PDF using /EmbeddedFiles
Inject into AcroForm text field values
Add annotations with text or link actions
Trigger predefined viewer actions CVEs â
Trigger out-of-band callbacks for blind detection CVEs â