When the application executes the JavaScript script embedded in the PDF within the sandbox, it fails to intercept some dangerous interfaces, which allows remote scripts to be loaded, resulting in arbitrary code execution.
References
| Link | Resource |
|---|---|
| https://www.foxit.com/support/security-bulletins.html | Vendor Advisory |
Configurations
History
16 Jun 2026, 16:43
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.foxit.com/support/security-bulletins.html - Vendor Advisory | |
| First Time |
Foxit
Foxit ai |
|
| CPE | cpe:2.3:a:foxit:ai:*:*:*:*:*:*:*:* |
15 Jun 2026, 12:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-15 12:16
Updated : 2026-06-16 16:43
NVD link : CVE-2026-12057
Mitre link : CVE-2026-12057
CVE.ORG link : CVE-2026-12057
JSON object : View
Products Affected
foxit
- ai
CWE
CWE-829
Inclusion of Functionality from Untrusted Control Sphere
