This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+4 more
Affected surfaces
ReleasePort's take
Moderate signalSixLabors.ImageSharp is upgraded from 1.0.4 to 2.1.13, removing seven published advisories related to image‑parsing vulnerabilities.
Why it matters: Patches seven security advisories in the ImageSharp dependency; upgrade to version 2.1.13 eliminates known parsing flaws.
Summary
AI summaryUpdates Verify, F2, and F1 across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Updates SixLabors.ImageSharp from 1.0.4 to 2.1.13, clearing seven published advisories in image parsing. Updates SixLabors.ImageSharp from 1.0.4 to 2.1.13, clearing seven published advisories in image parsing. Source: llm_adapter@2026-07-17 Confidence: high |
— |
| Feature | Medium |
Adds a full command-line interface with operations like --merge, --extract-pages, and --batch-resave. Adds a full command-line interface with operations like --merge, --extract-pages, and --batch-resave. Source: llm_adapter@2026-07-17 Confidence: high |
— |
| Feature | Medium |
Adds in-app bookmark editing: add, rename, nest, reorder, retarget, delete with multi-select and undo. Adds in-app bookmark editing: add, rename, nest, reorder, retarget, delete with multi-select and undo. Source: llm_adapter@2026-07-17 Confidence: high |
— |
| Feature | Medium |
Adds Redo functionality (Ctrl+Y or Ctrl+Shift+Z) across annotations, text edits, stamps, and document operations per tab. Adds Redo functionality (Ctrl+Y or Ctrl+Shift+Z) across annotations, text edits, stamps, and document operations per tab. Source: llm_adapter@2026-07-17 Confidence: high |
— |
| Feature | Medium |
Adds Jump history navigation (Alt+Left/Right, mouse back/forward) for bookmark, link, and page jumps. Adds Jump history navigation (Alt+Left/Right, mouse back/forward) for bookmark, link, and page jumps. Source: llm_adapter@2026-07-17 Confidence: high |
— |
| Feature | Medium |
Adds a visual keyboard view in the shortcuts overlay (F1) showing bound keys color‑coded by category. Adds a visual keyboard view in the shortcuts overlay (F1) showing bound keys color‑coded by category. Source: llm_adapter@2026-07-17 Confidence: high |
— |
| Feature | Low |
Adds Japanese OCR language support on demand. Adds Japanese OCR language support on demand. Source: granite4.1:30b@2026-07-17-audit Confidence: low |
— |
| Bugfix | Medium |
Fixes intermittent crash during scrolling or clicking caused by concurrent PDFium calls lacking proper locking. Fixes intermittent crash during scrolling or clicking caused by concurrent PDFium calls lacking proper locking. Source: llm_adapter@2026-07-17 Confidence: high |
— |
| Bugfix | Medium |
Fixes crash opening a PDF whose page tree parses to zero pages. Fixes crash opening a PDF whose page tree parses to zero pages. Source: llm_adapter@2026-07-17 Confidence: high |
— |
| Bugfix | Medium |
Fixes saving signed PDFs that shipped a dead signature value, now stripping it to pass strict validation. Fixes saving signed PDFs that shipped a dead signature value, now stripping it to pass strict validation. Source: llm_adapter@2026-07-17 Confidence: low |
— |
| Bugfix | Medium |
Fixes failure when saving over an open file on annotation‑only PDFs ("being used by another process" error). Fixes failure when saving over an open file on annotation‑only PDFs ("being used by another process" error). Source: llm_adapter@2026-07-17 Confidence: low |
— |
| Bugfix | Medium |
Fixes signed PDFs by stripping dead signature values instead of shipping invalid signatures. Fixes signed PDFs by stripping dead signature values instead of shipping invalid signatures. Source: granite4.1:30b@2026-07-17-audit Confidence: low |
— |
| Bugfix | Low |
Ensures saving never degrades PDF/A conformance; write engine patched and validated with veraPDF across a 2,900‑file corpus. Ensures saving never degrades PDF/A conformance; write engine patched and validated with veraPDF across a 2,900‑file corpus. Source: granite4.1:30b@2026-07-17-audit Confidence: low |
— |
Full changelog
KillerPDF 1.6.4 adds a full command-line interface, in-app bookmark editing, redo and jump history, and a visual keyboard view for shortcuts. It also introduces a standards-conformance guarantee: every release is now validated against veraPDF across a 2,900-file corpus, so saving a PDF never degrades it.
Added
- Command-line interface —
--merge,--extract-pages,--split,--decrypt,--to-image,--flatten,--print,--ocr, plus--batch-resave. Runs headless with real exit codes, works while the app is open, and reuses the exact pipelines the GUI runs. - Bookmark editing in the sidebar Outline panel — add, rename in place (F2), nest, reorder, retarget, delete, with multi-select and full undo (#133, thanks @alivio-israu).
- Redo — Ctrl+Y or Ctrl+Shift+Z, across annotations, text edits, stamps, and document operations, per tab.
- Jump history — Alt+Left / Alt+Right and the mouse back/forward buttons retrace bookmark, link, and page jumps, browser-style.
- Keyboard view in the shortcuts overlay (F1) — a visual keyboard with every bound key lit and color-coded by category, following the active theme and language.
- More big-viewer conventions: Home/End jump to first/last page, Ctrl+1/2/3 set actual size / fit width / fit page, and the Menu key opens the context menu at the selection.
- Japanese OCR language, on-demand like the rest.
Changed
- Shortcut remap: About is now F12, Document Info is F4 (Ctrl+D also works), F2 renames the selected bookmark, Settings gained F9, and F3 / Shift+F3 step search matches from anywhere.
- Continuous view: clicking a page no longer snap-scrolls it to the top — clicks are for tools and selection, and the current page follows the viewport (#128, thanks @Ryokoxx).
- German translation refinements (thanks @Mr-Update, #124, #126).
Fixed
- Saving no longer degrades PDF/A conformance. The write engine (PdfSharpCore) is now vendored and patched with six standards fixes, verified by a new veraPDF harness across a 2,900-file corpus. See
validation/RESULTS.md. - Fixed an intermittent crash while scrolling or clicking through a document: direct PDFium calls could collide with a background render inside the (single-threaded) engine. All direct calls now serialize on the same lock the renderer uses.
- Saving a signed PDF now strips the dead signature value instead of shipping one that fails strict validation.
- Saving over the open file no longer fails with "being used by another process" on annotation-only PDFs (#129, thanks @Peter5164).
- Fixed a crash opening a PDF whose page tree parses to zero pages (#130, thanks @demo1866).
- Bookmark titles in password-protected PDFs no longer show as mojibake (#133, thanks @alivio-israu).
- Grid view now tracks the current page while scrolling.
Security
- SixLabors.ImageSharp updated 1.0.4 → 2.1.13, clearing seven published advisories in image parsing (import, clipboard paste, signature images).
Verify
KillerPDF.exeis Authenticode-signed (Open Source Developer Stephen Riley).- SHA256 (exe):
9F64C3F4791347860D4010257792902063E2F4646607B278D59C654A58EC9A63 - Full hashes in
SHA256SUMS.txt.
Full changelog: CHANGELOG.md
Security Fixes
- dep: SixLabors.ImageSharp updated from 1.0.4 to 2.1.13, clearing seven published advisories in image parsing
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About SteveTheKiller/KillerPDF
All releases →Related context
Related tools
Beta — feedback welcome: [email protected]