Vulnerability Description
In JazzCore python-pdfkit 1.0.0, the from_string method enables the execution of JavaScript code within the context of the server application and the exfiltration of local files.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://habuon.github.io/2025/03/12/pdfkit-vulnerability-%28CVE-2025-26240%29.ht
- https://www.csirt.gov.sk/the-python-pdfkit-library-vulnerability.html
- https://habuon.github.io/2025/03/12/pdfkit-vulnerability-%28CVE-2025-26240%29.ht
FAQ
What is CVE-2025-26240?
CVE-2025-26240 is a vulnerability with a CVSS score of 8.4 (HIGH). In JazzCore python-pdfkit 1.0.0, the from_string method enables the execution of JavaScript code within the context of the server application and the exfiltration of local files.
How severe is CVE-2025-26240?
CVE-2025-26240 has been rated HIGH with a CVSS base score of 8.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-26240?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.