CVE-2026-12057

HIGH

DoS + Remote Code Execution via PDF JavaScript in Foxit AI

Title source: cna
STIX 2.1

Description

When the application executes the JavaScript script embedded in the PDF within the sandbox, it fails to intercept some dangerous interfaces, which allows remote scripts to be loaded, resulting in arbitrary code execution.

References (1)

Core 1

Scores

CVSS v3 8.6
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-829
Status published
Products (1)
Foxit Software Inc./Foxit AI before 2026-06-15
Published Jun 15, 2026
Tracked Since Jun 15, 2026