CVE-2026-12057 PUBLISHED

DoS + Remote Code Execution via PDF JavaScript in Foxit AI

Assigner: Foxit
Reserved: 12.06.2026 Published: 15.06.2026 Updated: 15.06.2026

When the application executes the JavaScript script embedded in the PDF within the sandbox, it fails to intercept some dangerous interfaces, which allows remote scripts to be loaded, resulting in arbitrary code execution.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
CVSS Score: 8.6

Product Status

Vendor Foxit Software Inc.
Product Foxit AI
Versions Default: unaffected
  • Version before 2026-06-15 is affected

Credits

  • mrfathoni finder

References

Problem Types

  • CWE-829 Inclusion of functionality from untrusted control sphere CWE

Impacts

  • CAPEC-175 Code Inclusion