CVE-2026-40505

low
Published 2026-04-16 · Modified 2026-05-26
CVSS v3
3.3
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
CVSS v2
VIR risk
3.3

Description

MuPDF before 1.27 contains an ANSI injection vulnerability in mutool that allows attackers to inject arbitrary ANSI escape sequences through crafted PDF metadata fields. Attackers can embed malicious ANSI escape codes in PDF metadata that are passed unsanitized to terminal output when running mutool info, enabling them to manipulate terminal display for social engineering attacks such as presenting fake prompts or spoofed commands.

Predictions

Exploit likelihood
34%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2026-40505

vendor Authored 2026-05-27

Vendor advisory: disclosure@vulncheck.com — https://github.com/ArtifexSoftware/mupdf/commit/0f17d789fe8c29b41e47663be82514aaca3a4dfb

vendor Authored 2026-05-27

Vendor advisory: disclosure@vulncheck.com — https://cgit.ghostscript.com/cgi-bin/cgit.cgi/mupdf.git/commit/?id=0f17d789fe8c29b41e47663be82514aaca3a4dfb

OS impact

OSVersionStatusFixed in
debian debianbookwormaffected
debian debianbullseyeaffected
debian debianforkyfixed1.27.0+ds1-5
debian debiansidfixed1.27.0+ds1-5
debian debiantrixieaffected

Application impact

VendorProductVersionsFixed
artifexmupdf{"endExcluding":"1.27.0"}1.27.0

References

CWEs

CWE-150

Verify integrity in audit chain (admin only). AS-IS.