Executive brief
Foxit PDF Editor and Reader are widely used desktop applications for creating, editing, and viewing PDF documents. A vulnerability in how these applications handle attachment file names allows malicious PDF files to extract attachments outside the intended secure directory when opened, potentially overwriting system files or placing malware on the user's computer. No active exploitation in the wild has been reported.
Technical details
The vulnerability is a directory traversal flaw in attachment file name validation that allows path traversal sequences (e.g., "../") in embedded file names to escape the secure attachment directory. An attacker can craft a malicious PDF with specially crafted attachment file names that, when the PDF is opened and the attachment is extracted, write files to arbitrary locations on the file system. The flaw affects multiple versions across both products; patches are available in Foxit PDF Reader 2026.2.1 and Foxit PDF Editor 2026.2.1/14.0.8 and later.
Affected products
- Foxit PDF Reader 2026.2.0.39747 and earlier
- Foxit PDF Editor 2026.2.0.39747 and all previous 2026.x versions, 2025.3.0.35737 and all previous 2025.x versions, 2024.4.1.27687 and all previous 2024.x versions, 2023.3.0.23028 and all previous 2023.x versions, 14.0.7.33751 and all previous 14.x versions, 13.2.6.24111 and earlier
Timeline
- 2026-09-23: disclosed
- 2026-09-23: patched: Foxit PDF Reader 2026.2.1 and Foxit PDF Editor 2026.2.1/14.0.8 released