CVE-2025-26240

NameCVE-2025-26240
DescriptionIn JazzCore python-pdfkit 1.0.0, the from_string method enables the execution of JavaScript code within the context of the server application and the exfiltration of local files.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
pdfkit (PTS)bullseye0.6.1-2vulnerable
bookworm1.0.0-2vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
pdfkitsource(unstable)(unfixed)

Notes

https://habuon.github.io/2025/03/12/pdfkit-vulnerability-%28CVE-2025-26240%29.html

Search for package or bug name: Reporting problems