CVE-2025-26240

EUVD-2025-210273
In JazzCore python-pdfkit 1.0.0, the from_string method enables the execution of JavaScript code within the context of the server application and the exfiltration of local files.
Classic Buffer Overflow
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.4 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 32.81%
Debian logo
Debian Releases
Debian Product
Codename
pdfkit
bookworm
postponed
bullseye
postponed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
pdfkit
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
dne