Description
The input file does not need to be strictly in a structurally valid PDF format. Instead, after reviewing the content, the original document disguised as a PDF will be sent to the parser. Malicious documents will construct malicious external entities that, through the protocol, point to local paths, thereby allowing access to any local files within the user's permission range.
Severity (CVSS)
| Base score | 6.5 |
|---|---|
| Severity | Medium |
| Version | CVSS 3.1 |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
| Provided by | CNA |
Weaknesses
- CWE-611 — Improper Restriction of XML External Entity Reference (CWE-611)
Affected products
| Vendor | Product | Versions |
|---|---|---|
| Foxit Software Inc. | Foxit PDF Editor | Versions 2026.1.1 and earlier; Versions 14.0.4 and earlier; Versions 13.2.4 and earlier |
| Foxit Software Inc. | Foxit PDF Reader | Versions 2026.1.1 and earlier |
References
Generated from the official CVE List on 09 Jul 2026 07:08 UTC.