CVE-2026-57259

Published Jul 8, 2026

Last updated 2 months ago

Overview

Description
The input file does not need to be strictly in a structurally valid PDF format. Instead, after reviewing the content, the original document disguised as a PDF will be sent to the parser. Malicious documents will construct malicious external entities that, through the protocol, point to local paths, thereby allowing access to any local files within the user's permission range.
Source
14984358-7092-470d-8f34-ade47a7658a2
NVD status
Analyzed
Products
pdf_editor, pdf_reader

Risk scores

CVSS 3.1

Type
Secondary
Base score
6.5
Impact score
3.6
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Severity
MEDIUM

Weaknesses

14984358-7092-470d-8f34-ade47a7658a2
CWE-611

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.