Home
HIGH: 8.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HDefault status
unaffected
before 2026-06-15
affected
Description
When the application executes the JavaScript script embedded in the PDF within the sandbox, it fails to intercept some dangerous interfaces, which allows remote scripts to be loaded, resulting in arbitrary code execution.
Problem types
CWE-829 Inclusion of functionality from untrusted control sphere
Product status
before 2026-06-15
Credits
mrfathoni
References
www.foxit.com/support/security-bulletins.html