In JazzCore python-pdfkit 1.0.0, the from_string method enables the execution of JavaScript code within the context of the server application and the exfiltration of local files.
Metrics
Affected Vendors & Products
References
History
Thu, 18 Jun 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In JazzCore python-pdfkit 1.0.0, the from_string method enables the execution of JavaScript code within the context of the server application and the exfiltration of local files. | |
| Weaknesses | CWE-120 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-06-17T17:27:07.439Z
Reserved: 2025-02-07T00:00:00.000Z
Link: CVE-2025-26240
Updated: 2026-06-17T17:27:02.773Z
No data.
No data.
OpenCVE Enrichment
No data.