Foxit PDF Editor Vulnerabilities Let Attackers Execute Arbitrary JavaScript
Security updates for Foxit PDF Editor Cloud have addressed critical cross-site scripting (XSS) vulnerabilities that could allow attackers to execute arbitrary JavaScript code in users' browsers.
Security updates for Foxit PDF Editor Cloud have addressed critical cross-site scripting (XSS) vulnerabilities that could allow attackers to execute arbitrary JavaScript code in users' browsers.
The identified vulnerabilities were found in the application’s File Attachments list and Layers panel, where insufficient input validation and improper output encoding enabled the execution of malicious code. These vulnerabilities, tracked as CVE-2026-1591 and CVE-2026-1592, stem from inadequate sanitization of user inputs in layer names and attachment file names.
The vulnerabilities fall under the classification of CWE-79 (Cross-site Scripting) with a CVSS 3.0 score of 6.3, indicating moderate severity. The attack vector is network-based (AV:N) with low attack complexity (AC:L), requiring low privileges (PR:L) and user interaction (UI:R). The impact assessment indicates a high confidentiality risk, limited integrity impact, and no availability impact.
CVE ID: CVE-2026-1591, CVE-2026-1592 Vulnerability Type: Cross-site Scripting (CWE-79) CVSS Score: 6.3 Severity: Moderate Impact: Arbitrary JavaScript Execution
The vulnerabilities fall under the classification of CWE-79 (Cross-site Scripting) with a CVSS 3.0 score of 6.3, indicating moderate severity.
Foxit has released security patches to address these vulnerabilities as part of the February 3, 2026 update for Foxit PDF Editor Cloud. No user action is required for Cloud versions, as updates are automatically deployed. Users of desktop versions should ensure their applications are updated through the in-app update mechanism.
Organizations using Foxit PDF Editor are advised to verify that their installations are running the latest patched version. Additionally, reviewing file handling practices and limiting user access to PDF editing features within organizational security policies is recommended.
For security inquiries, Foxit’s Security Response Team can be contacted at security-ml@foxit.com . Additional security advisories are available on Foxit's official security page .
Based on reporting by Cyber Security News.
