Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-26240

Опубликовано: 17 июн. 2026
Источник: nvd
CVSS3: 8.4
EPSS Низкий

Описание

In JazzCore python-pdfkit 1.0.0, the from_string method enables the execution of JavaScript code within the context of the server application and the exfiltration of local files.

EPSS

Процентиль: 32%
0.00392
Низкий

8.4 High

CVSS3

Дефекты

CWE-120

Связанные уязвимости

CVSS3: 8.4
ubuntu
3 месяца назад

In JazzCore python-pdfkit 1.0.0, the from_string method enables the execution of JavaScript code within the context of the server application and the exfiltration of local files.

CVSS3: 8.4
debian
3 месяца назад

In JazzCore python-pdfkit 1.0.0, the from_string method enables the ex ...

CVSS3: 8.4
github
3 месяца назад

pdfkit: Path traversal in from_string

EPSS

Процентиль: 32%
0.00392
Низкий

8.4 High

CVSS3

Дефекты

CWE-120