Tracker / CVE-2026-57259
CVE-2026-57259
Medium 6.5
The input file does not need to be strictly in a structurally valid PDF format. Instead, after reviewing the content, the original document disguised as a PDF will be sent to the parser. Malicious documents will construct malicious external entities that, through the protocol, point to local paths, thereby allowing access to any local files within the user's permission range.
Affected products and versions
| foxit | pdf_editor · … → 13.2.4.24048 |
|---|---|
| foxit | pdf_editor · 14.0.0.33046 → 14.0.4.33508 |
| foxit | pdf_editor · 2023.1.0.15510 → 2023.3.0.23028 |
| foxit | pdf_editor · 2024.1.0.23997 → 2024.4.1.27687 |
| foxit | pdf_editor · 2025.1.0.27937 → 2025.3.0.35737 |
| foxit | pdf_editor · 2026.1.0.36452 → 2026.1.1.36485 |
| foxit | pdf_reader · … → 2026.1.1.36485 |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.