VYPR
Critical severity9.8NVD Advisory· Published Dec 15, 2021· Updated Jun 17, 2026

CVE-2021-43113

CVE-2021-43113

Description

iTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 allows command injection via a CompareTool filename that is mishandled on the gs (aka Ghostscript) command line in GhostscriptHelper.java.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
com.itextpdf:itext7-coreMaven
< 7.1.177.1.17
com.itextpdf:itextpdfMaven
< 5.5.13.35.5.13.3

Affected products

6

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.