Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-26240

Опубликовано: 17 июн. 2026
Источник: debian

Описание

In JazzCore python-pdfkit 1.0.0, the from_string method enables the execution of JavaScript code within the context of the server application and the exfiltration of local files.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
pdfkitremovedpackage
pdfkitpostponedbookwormpackage
pdfkitpostponedbullseyepackage

Примечания

  • https://habuon.github.io/2025/03/12/pdfkit-vulnerability-%28CVE-2025-26240%29.html

Связанные уязвимости

CVSS3: 8.4
ubuntu
3 месяца назад

In JazzCore python-pdfkit 1.0.0, the from_string method enables the execution of JavaScript code within the context of the server application and the exfiltration of local files.

CVSS3: 8.4
nvd
3 месяца назад

In JazzCore python-pdfkit 1.0.0, the from_string method enables the execution of JavaScript code within the context of the server application and the exfiltration of local files.

CVSS3: 8.4
github
3 месяца назад

pdfkit: Path traversal in from_string