CVE-2026-12057

When the application executes the JavaScript script embedded in the PDF within the sandbox, it fails to intercept some dangerous interfaces, which allows remote scripts to be loaded, resulting in arbitrary code execution.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:foxit:ai:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-06-15 12:16

Updated : 2026-06-17 10:14


NVD link : CVE-2026-12057

Mitre link : CVE-2026-12057

CVE.ORG link : CVE-2026-12057


JSON object : View

Products Affected

foxit

  • ai
CWE
CWE-829

Inclusion of Functionality from Untrusted Control Sphere