Security fixes are made on the latest public version and the current default branch.
PdfCrop is still before version 1.0. Project files have a format version, but old application versions may not receive security fixes.
Do not open a public issue with security details.
Use Security → Report a vulnerability in the GitHub repository to send a private report. If private reporting is not available, email security@codingberry.com. Share only enough information by email to start a private conversation.
Please include:
- The affected PdfCrop version
- The possible impact
- Steps or a file that reproduce the problem
- A suggested fix, if you have one
The maintainers will reply as soon as practical. They will work with the reporter before making the problem public.
PdfCrop processes untrusted PDF files on the local computer. Reports about PDF parsers, native commands, paths, project-source checks, PDF permissions, and communication with qpdf are especially useful.