Executive brief
pdfforge PDF Architect is a PDF editing and creation application used by individuals and organizations. A memory corruption vulnerability in its PDF file parser allows attackers to execute arbitrary code if a user opens a malicious PDF file or visits a compromised website hosting a malicious PDF. This could lead to complete system compromise, data theft, or ransomware installation on an affected user's computer.
Technical details
The vulnerability is a memory corruption flaw in pdfforge PDF Architect's PDF file parsing engine caused by improper validation of user-supplied data. The attack requires local access vector (user must open a file or visit a page) but does not require authentication or elevated privileges. A remote attacker can craft a malicious PDF that, when opened by a user in PDF Architect, triggers the memory corruption condition and achieves remote code execution in the context of the application process. No patch is currently available based on the disclosure timeline; the vendor was notified on 2026-02-12 and acknowledged receipt on 2026-03-23, but no fix has been released as of the advisory publication date.
Affected products
- pdfforge PDF Architect
Timeline
- 2026-02-12: disclosed: Vulnerability reported to pdfforge
- 2026-03-23: other: Vendor acknowledged receipt of report
- 2026-08-31: advisory: ZDI public advisory released (ZDI-26-613); marked as 0-day at time of publication