CVE-2026-12057
HIGHDoS + Remote Code Execution via PDF JavaScript in Foxit AI
Title source: cnaDescription
When the application executes the JavaScript script embedded in the PDF within the sandbox, it fails to intercept some dangerous interfaces, which allows remote scripts to be loaded, resulting in arbitrary code execution.
References (1)
Core 1
Core References
Scores
CVSS v3
8.6
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-829
Status
published
Products (1)
Foxit Software Inc./Foxit AI
before 2026-06-15
Published
Jun 15, 2026
Tracked Since
Jun 15, 2026