In JazzCore python-pdfkit 1.0.0, the from_string method enables the execution of JavaScript code within the context of the server application and the exfiltration of local files.
Project Subscriptions
No data.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-9g3x-6x24-vf9f | pdfkit: Path traversal in from_string |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 18 Jun 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Python-pdfkit from_string Method Allows Server-Side JavaScript Execution and Local File Exfiltration |
Thu, 18 Jun 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In JazzCore python-pdfkit 1.0.0, the from_string method enables the execution of JavaScript code within the context of the server application and the exfiltration of local files. | |
| Weaknesses | CWE-120 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-06-17T17:27:07.439Z
Reserved: 2025-02-07T00:00:00.000Z
Link: CVE-2025-26240
Updated: 2026-06-17T17:27:02.773Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-18T17:45:13Z
Weaknesses
Github GHSA