CVE-2025-26525

CVSS 3.1 Score 8.6 of 10 (high)

Details

Published Feb 24, 2025
CWE ID 552

Summary

CVE-2025-26525 is a vulnerability affecting systems with pdfTeX installed. The issue stems from insufficient sanitization in the TeX notation filter. This weakness allows an attacker to read arbitrary files on affected systems, posing a significant risk to system security. The TeX Live distribution is particularly vulnerable to this issue, as it includes pdfTeX by default. System administrators and users are advised to apply the necessary patches or updates to mitigate this arbitrary file read vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share