Description

The input file does not need to be strictly in a structurally valid PDF format. Instead, after reviewing the content, the original document disguised as a PDF will be sent to the parser. Malicious documents will construct malicious external entities that, through the protocol, point to local paths, thereby allowing access to any local files within the user's permission range.

Severity (CVSS)

Base score6.5
SeverityMedium
VersionCVSS 3.1
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Provided byCNA

Weaknesses

  • CWE-611 — Improper Restriction of XML External Entity Reference (CWE-611)

Affected products

VendorProductVersions
Foxit Software Inc.Foxit PDF EditorVersions 2026.1.1 and earlier; Versions 14.0.4 and earlier; Versions 13.2.4 and earlier
Foxit Software Inc.Foxit PDF ReaderVersions 2026.1.1 and earlier

References

Authoritative sources

This page is a snapshot. For the latest enrichment and updates, view the record on CVE.org or the NVD.

Generated from the official CVE List on 09 Jul 2026 07:08 UTC.