Medium severity6.1NVD Advisory· Published Sep 2, 2025· Updated Jun 17, 2026
CVE-2025-51966
CVE-2025-51966
Description
A cross-site scripting (XSS) vulnerability exists in the PDF preview functionality of uTools thru 7.1.1. When a user previews a specially crafted PDF file, embedded JavaScript code executes within the application's privileged context, potentially allowing attackers to steal sensitive data or perform unauthorized actions.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
2- t1sts.github.io/2025/05/27/uTools-has-an-XSS-vulnerability/nvdExploitThird Party Advisory
- t1sts.github.io/2025/09/01/CVE-2025-51966/nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.