CVE-2025-26240
Received
Received - Intake
Remote Code Execution in python-pdfkit
Publication date: 2026-06-17
Last updated on: 2026-06-17
Assigner: MITRE
Description
Description
In JazzCore python-pdfkit 1.0.0, the from_string method enables the execution of JavaScript code within the context of the server application and the exfiltration of local files.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
Currently, no data is known.
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |