CVE-2025-26240 - CERT CVE
ID CVE-2025-26240
Sažetak In JazzCore python-pdfkit 1.0.0, the from_string method enables the execution of JavaScript code within the context of the server application and the exfiltration of local files.
Reference
CVSS
Base: 8.4
Impact: 5.9
Exploitability:2.5
Pristup
VektorSloženostAutentikacija
LOCAL LOW NONE
Impact
PovjerljivostCjelovitostDostupnost
HIGH HIGH HIGH
CVSS vektor CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Zadnje važnije ažuriranje 22-06-2026 - 20:42
Objavljeno 17-06-2026 - 17:16