Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
open-source-dependency-vulnerabilityendpoint-software-vulnerabilityproof-of-concept-release

PDF Ecosystem Vulnerabilities Enable One-Click Attacks and PDF Object Injection

Updated 3mo agoFirst seen Feb 23, 20262 sources

Security researchers reported multiple previously unknown weaknesses across the PDF ecosystem that can be exploited through crafted documents. Novee Security’s research into Foxit and Apryse PDF platforms described 13 vulnerability categories and 16 exploit paths, including critical XSS and OS command injection, with “one-click” scenarios where simply opening a document could trigger compromise and potentially enable account takeover or backend command execution.

Separately, a high-severity flaw in the widely used jsPDF library was disclosed as CVE-2026-25755 (CVSS 8.8), enabling PDF object injection via improper sanitization in the addJS method. By breaking out of the /JS (...) string (e.g., injecting ) >> /Action ...), an attacker can inject arbitrary PDF structures and actions such as /OpenAction, potentially triggering behavior even when JavaScript is disabled in the viewer and enabling document manipulation (e.g., altering /Annots or /Signatures) across different PDF viewers, including lightweight mobile/embedded parsers.

Share:
PDF Ecosystem Vulnerabilities Enable One-Click Attacks and PDF Object Injection
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Feb 23, 20264mo ago

jsPDF 4.1.0 recommended to mitigate CVE-2026-25755

By 2026-02-23, guidance accompanying disclosure of CVE-2026-25755 recommended upgrading to jsPDF 4.1.0 or later and avoiding addJS with untrusted input until patched. Additional mitigation advice included strict input validation to prevent malicious PDF object injection.

Researcher ZeroXJacks reports jsPDF object injection flaw

Researcher ZeroXJacks disclosed a high-severity jsPDF vulnerability, tracked as CVE-2026-25755, affecting the addJS method and enabling PDF Object Injection through improper sanitization of user-controlled input. The researcher also demonstrated a proof of concept showing how crafted payloads could inject PDF structures and trigger actions such as /OpenAction.

Feb 18, 20264mo ago

Novee Security releases PDF platform vulnerability study

On 2026-02-18, Novee Security published a study on Foxit and Apryse PDF systems identifying 13 vulnerability categories and 16 exploitation paths, including one-click attack scenarios, account takeover, and backend command execution risks. The researchers said they had coordinated disclosure with Foxit and Apryse and that CVEs were assigned to support patching.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

9 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.