CVE-2025-26240
the affected product
In JazzCore python-pdfkit 1.0.0, the from_string method enables the execution of JavaScript code within the context of the server application and the exfiltration of local files.
- CVSS
- 8.4
- EPSS
- 0.39% 31.9% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.18