Executive brief
Foxit PDF Editor and Reader, widely used tools for viewing and editing PDF documents, contain a path traversal vulnerability in how they handle embedded PDF resources. An attacker could exploit this by crafting a malicious PDF that writes files to arbitrary locations on a user's system, potentially leading to arbitrary code execution when the document is opened.
Technical details
A path traversal vulnerability exists in the PDF resource file path validation logic, allowing insufficient validation of resource file paths during embedded PDF processing. The vulnerability can be exploited via a crafted PDF document opened by a local user, enabling arbitrary file writes outside intended directories and potential arbitrary code execution.
Affected products
- Foxit PDF Reader 2026.2.0.39747 and earlier
- Foxit PDF Editor 2026.2.0.39747 and all previous 2026.x versions, 2025.3.0.35737 and all previous 2025.x versions, 2024.4.1.27687 and all previous 2024.x versions, 2023.3.0.23028 and all previous 2023.x versions, 14.0.7.33751 and all previous 14.x versions, 13.2.6.24111 and earlier
Timeline
- 2026-09-23: disclosed
- 2026-09-23: patched: Fixed in Foxit PDF Reader 2026.2.1 and Foxit PDF Editor 2026.2.1/14.0.8