HarborGuard / CVE
Back to search
CRITICALCVE-2026-41552Published Modified CNA CERT-PL

CVE-2026-41552: Path Traversal in PDF Export Module

PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Path Traversal due to lack of HTML sanitization. An unauthenticated user could craft the html payload which could include local files from the server and display them in the generated PDF. This issue was fixed in PDF Export Module version 0.7.6.

Metrics

CVSS v4.0
9.2
Severity
CRITICAL
Fixed in
0.7.6
Affected Products
1

Fix available

0.7.6
Affected packages
  • DHTMLX / PDF Export Module
    < 0.7.6 (from 0.3.3)
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N