PDF Ecosystem Vulnerabilities Enable One-Click Attacks and PDF Object Injection
Security researchers reported multiple previously unknown weaknesses across the PDF ecosystem that can be exploited through crafted documents. Novee Security’s research into Foxit and Apryse PDF platforms described 13 vulnerability categories and 16 exploit paths, including critical XSS and OS command injection, with “one-click” scenarios where simply opening a document could trigger compromise and potentially enable account takeover or backend command execution.
Separately, a high-severity flaw in the widely used jsPDF library was disclosed as CVE-2026-25755 (CVSS 8.8), enabling PDF object injection via improper sanitization in the addJS method. By breaking out of the /JS (...) string (e.g., injecting ) >> /Action ...), an attacker can inject arbitrary PDF structures and actions such as /OpenAction, potentially triggering behavior even when JavaScript is disabled in the viewer and enabling document manipulation (e.g., altering /Annots or /Signatures) across different PDF viewers, including lightweight mobile/embedded parsers.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
3 events from the most recent confirmed update back to the earliest known activity.
jsPDF 4.1.0 recommended to mitigate CVE-2026-25755
By 2026-02-23, guidance accompanying disclosure of CVE-2026-25755 recommended upgrading to jsPDF 4.1.0 or later and avoiding addJS with untrusted input until patched. Additional mitigation advice included strict input validation to prevent malicious PDF object injection.
Researcher ZeroXJacks reports jsPDF object injection flaw
Researcher ZeroXJacks disclosed a high-severity jsPDF vulnerability, tracked as CVE-2026-25755, affecting the addJS method and enabling PDF Object Injection through improper sanitization of user-controlled input. The researcher also demonstrated a proof of concept showing how crafted payloads could inject PDF structures and trigger actions such as /OpenAction.
Novee Security releases PDF platform vulnerability study
On 2026-02-18, Novee Security published a study on Foxit and Apryse PDF systems identifying 13 vulnerability categories and 16 exploitation paths, including one-click attack scenarios, account takeover, and backend command execution risks. The researchers said they had coordinated disclosure with Foxit and Apryse and that CVEs were assigned to support patching.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
2 references tracked. Mallory keeps watching after this page renders.
See the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


