Executive brief
Foxit PDF Reader and Editor are popular tools for viewing and managing PDF documents. A security flaw allows specially crafted files, disguised as PDFs, to trick the software into accessing sensitive local files on a user's computer. If a user opens one of these malicious files, an attacker could potentially steal private data or system information within the user's permission level.
Technical details
An XML External Entity (XXE) vulnerability (CWE-611) exists in Foxit PDF Reader and Editor. The application fails to strictly validate that input files conform to the PDF structure, allowing documents disguised as PDFs to be passed to an internal parser. An attacker can craft a malicious document containing external entities that point to local file paths. When a user opens the file, the parser resolves these entities, allowing the attacker to access any local files within the scope of the user's permissions. This is a network-based attack requiring user interaction (opening a file). The issue is resolved in version 2026.1.2.
Affected products
- Foxit Software Inc. Foxit PDF Editor 2026.1.1 and earlier, 14.0.4 and earlier, 13.2.4 and earlier
- Foxit Software Inc. Foxit PDF Reader 2026.1.1 and earlier
Timeline
- 2026-07-08: disclosed
- 2026-07-08: advisory
- 2026-07-08: patched