CVE-2025-15569

HIGH

Artifex MuPDF <1.26.1 - Path Traversal

Title source: llm
STIX 2.1

Description

A flaw has been found in Artifex MuPDF up to 1.26.1 on Windows. The impacted element is the function get_system_dpi of the file platform/x11/win_main.c. This manipulation causes uncontrolled search path. The attack requires local access. The attack is considered to have high complexity. The exploitability is regarded as difficult. Upgrading to version 1.26.2 is sufficient to resolve this issue. Patch name: ebb125334eb007d64e579204af3c264aadf2e244. Upgrading the affected component is recommended.

Scores

CVSS v3 7.0
EPSS 0.0002
EPSS Percentile 3.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-426 CWE-427
Status published
Products (3)
Artifex/MuPDF 1.26.0
Artifex/MuPDF 1.26.1
Artifex/MuPDF 1.26.2
Published Feb 10, 2026
Tracked Since Feb 18, 2026