FoxitCVE-2026-91797
Foxit PDF: path traversal
High7.8CVE-2026-91797 · Published Sep 23, 2026
Foxit PDF Editor/Reader failed to validate the directory traversal path in the attachment file name, resulting in malicious attachments being able to be written to directories outside the expected secure area when the PDF is opened.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Foxit PDF Editor Product | <= Versions 2026.2 and earlier | No fix yet |
| <= Versions 14.0.7 and earlier | No fix yet | |
| <= Versions 13.2.6 and earlier | No fix yet | |
| Foxit PDF Reader Product | <= Versions 2026.2 and earlier | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-73
More Foxit advisories
All Foxit| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 23 | Foxit PDF: out-of-bounds read | Medium6.1 | No fix yet |
| Sep 23 | Foxit PDF: use after free | High7.8 | No fix yet |
| Sep 23 | Foxit PDF: use after free | High7.8 | No fix yet |
| Sep 23 | Foxit PDF: out-of-bounds read | Medium6.1 | No fix yet |
| Sep 23 | Foxit PDF: out-of-bounds write | High7.8 | No fix yet |
| Sep 23 | Foxit PDF: code execution | High7.9 | No fix yet |