PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Path Traversal due to lack of HTML sanitization. An unauthenticated user could craft the html payload which could include
local files from the server and display them in the generated PDF.
This issue was fixed in PDF Export Module version 0.7.6.
local files from the server and display them in the generated PDF.
This issue was fixed in PDF Export Module version 0.7.6.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 15 May 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Path Traversal due to lack of HTML sanitization. An unauthenticated user could craft the html payload which could include local files from the server and display them in the generated PDF. This issue was fixed in PDF Export Module version 0.7.6. | |
| Title | Path Traversal in PDF Export Module | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2026-05-15T13:14:32.252Z
Reserved: 2026-04-21T12:09:57.293Z
Link: CVE-2026-41552
No data.
Status : Received
Published: 2026-05-15T13:16:18.990
Modified: 2026-05-15T13:16:18.990
Link: CVE-2026-41552
No data.
OpenCVE Enrichment
No data.
Weaknesses