When the application executes the JavaScript script embedded in the PDF within the sandbox, it fails to intercept some dangerous interfaces, which allows remote scripts to be loaded, resulting in arbitrary code execution.
References
| Link | Resource |
|---|---|
| https://www.foxit.com/support/security-bulletins.html | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-06-15 12:16
Updated : 2026-06-17 10:14
NVD link : CVE-2026-12057
Mitre link : CVE-2026-12057
CVE.ORG link : CVE-2026-12057
JSON object : View
Products Affected
foxit
- ai
CWE
CWE-829
Inclusion of Functionality from Untrusted Control Sphere
