{"id":"CVE-2025-26240","aliases":["PYSEC-2026-2860"],"url":"https://o3.security/vulnerability/CVE-2025-26240","summary":"pdfkit: Path traversal in from_string","details":"In JazzCore python-pdfkit 1.0.0, the from_string method enables the execution of JavaScript code within the context of the server application and the exfiltration of local files.","published":"2026-06-17T18:35:56Z","modified":"2026-07-13T16:43:38.165698783Z","cvss":{"score":8.4,"severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.00392,"percentile":0.31993,"asOf":"2026-08-10"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"pdfkit","fixedVersion":null}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-26240"},{"type":"PACKAGE","url":"https://github.com/JazzCore/python-pdfkit"},{"type":"WEB","url":"https://habuon.github.io/2025/03/12/pdfkit-vulnerability-%28CVE-2025-26240%29.html"},{"type":"WEB","url":"https://www.csirt.gov.sk/the-python-pdfkit-library-vulnerability.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-13T16:43:38.165698783Z"}}