Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-26240

Опубликовано: 17 июн. 2026
Источник: ubuntu
Приоритет: medium
CVSS3: 8.4

Описание

In JazzCore python-pdfkit 1.0.0, the from_string method enables the execution of JavaScript code within the context of the server application and the exfiltration of local files.

РелизСтатусПримечание
devel

DNE

esm-apps/bionic

needs-triage

esm-apps/focal

needs-triage

esm-apps/jammy

needs-triage

esm-apps/noble

needs-triage

jammy

needs-triage

noble

needs-triage

resolute

DNE

upstream

needs-triage

Показывать по

8.4 High

CVSS3

Связанные уязвимости

CVSS3: 8.4
nvd
3 месяца назад

In JazzCore python-pdfkit 1.0.0, the from_string method enables the execution of JavaScript code within the context of the server application and the exfiltration of local files.

CVSS3: 8.4
debian
3 месяца назад

In JazzCore python-pdfkit 1.0.0, the from_string method enables the ex ...

CVSS3: 8.4
github
3 месяца назад

pdfkit: Path traversal in from_string

8.4 High

CVSS3