MuPDF before 1.27 contains an ANSI injection vulnerability in mutool that allows attackers to inject arbitrary ANSI escape sequences through crafted PDF metadata fields. Attackers can embed malicious ANSI escape codes in PDF metadata that are passed unsanitized to terminal output when running mutool info, enabling them to manipulate terminal display for social engineering attacks such as presenting fake prompts or spoofed commands.
References
Configurations
History
No history.
Information
Published : 2026-04-16 02:16
Updated : 2026-06-17 10:45
NVD link : CVE-2026-40505
Mitre link : CVE-2026-40505
CVE.ORG link : CVE-2026-40505
JSON object : View
Products Affected
artifex
- mupdf
CWE
CWE-150
Improper Neutralization of Escape, Meta, or Control Sequences
