VYPR
High severity8.6NVD Advisory· Published Jun 15, 2026

CVE-2026-12057

CVE-2026-12057

Description

Foxit AI fails to sandbox dangerous JS interfaces in PDFs, allowing remote script loading leading to arbitrary code execution.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Foxit AI fails to sandbox dangerous JS interfaces in PDFs, allowing remote script loading leading to arbitrary code execution.

Vulnerability

Foxit AI (https://ai.foxit.com/) contains a sandbox escape vulnerability identified as CVE-2026-12057. When the application executes JavaScript embedded in a PDF within its sandbox, it fails to intercept some dangerous interfaces, allowing remote scripts to be loaded. This affects Foxit AI prior to the security update released on June 15, 2026 [1].

Exploitation

An attacker can craft a malicious PDF containing JavaScript that abuses the unblocked interfaces to load remote scripts. No authentication is required beyond convincing the victim to open the PDF with the affected Foxit AI application. The sandbox bypass occurs at the moment the embedded script executes and successfully loads a remote payload [1].

Impact

Successful exploitation leads to arbitrary code execution outside the sandbox, in the context of the user running Foxit AI. This gives the attacker the same privileges as the logged-in user, potentially leading to full compromise of the host system, data theft, or further lateral movement [1].

Mitigation

Foxit released a security update on June 15, 2026 that addresses the issue. No customer action is required for Foxit AI as the update is applied server-side. Users should ensure they are running the latest version of the service. No workarounds are provided; the fix is the definitive mitigation [1].

AI Insight generated on Jun 15, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.