I'd expect enterprising bad actors to upload malicious PDFs and rent out compromised machines.
Site operators could potentially re-render uploads and inject their own exploits.
Site operators could potentially re-render uploads and inject their own exploits.