Logo
vulnerabilityCVE-2026-40505
Name
CVE-2026-40505
Source
NVD ( link)Debian ( link)
Description
MuPDF before 1.27 contains an ANSI injection vulnerability in mutool that allows attackers to inject arbitrary ANSI escape sequences through crafted PDF metadata fields. Attackers can embed malicious ANSI escape codes in PDF metadata that are passed unsanitized to terminal output when running mutool info, enabling them to manipulate terminal display for social engineering attacks such as presenting fake prompts or spoofed commands.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
mupdf
Exploitable

Vulnerability Ratings#


4.8
CVSSv4
3.3
CVSSv31
NaN
other

Others affected component#


Name
Project
Project Version
Version
Status
buildroot
master
1.23.9
Exploitable