CVE-2025-26240
HIGH
NVD
CVSS Score
8.4
Severity
HIGH
Published
Jun 17, 2026
Vendor
unknown
Description
In JazzCore python-pdfkit 1.0.0, the from_string method enables the execution of JavaScript code within the context of the server application and the exfiltration of local files.