CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2026-41552

CVSS 9.2v4.0pub. 2026-05-15upd. 2026-05-19

PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Path Traversal due to lack of HTML sanitization. An unauthenticated user could craft the html payload which could include local files from the server and display them in the generated PDF. This issue was fixed in PDF Export Module version 0.7.6.

🤖 AI Analysis
How it works

The vulnerability results from insufficient sanitization of HTML data passed to the PDF export module. An attacker can craft a malicious HTML payload containing references to local server system files. The module processes such payload without path validation, resulting in the inclusion of the contents of the specified files in the generated PDF. The attack requires no authentication.

Impact

An attacker can read arbitrary files accessible to the server process, including potentially configuration files, keys, credentials, or other sensitive system resources. This results in high data confidentiality impact in both the local system context and related systems.

Mitigation & patch

The PDF Export Module should be updated to version 0.7.6 or later, in which the vendor has patched vulnerabilities related to file reading. Details are available in the vendor documentation: https://docs.dhtmlx.com/gantt/guides/pdf-export-module-whatsnew/

Who is affected

PDF Export Module in versions below 0.7.6, used in DHTMLX Gantt and DHTMLX Scheduler products

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Dhtmlx Pdf Export Module

    APP
    Dhtmlx
    0.3.3 – 0.7.6 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Path Traversal
CWE
References

Related vulnerabilities

CVE-2026-41553CRITICAL10.0PL ✓same product

RCE i command injection w PDF Export Module DHTMLX (Gantt/Scheduler)

CVE-2024-55213MEDIUM6.5same vendor

Directory Traversal vulnerability in dhtmlxFileExplorer v.8.4.6 allows a remote attacker to obtain sensitive i...

CVE-2024-55214MEDIUM6.5same vendor

Local File Inclusion vulnerability in dhtmlxFileExplorer v.8.4.6 allows a remote attacker to obtain sensitive ...

CVE-2013-6281MEDIUM4.3same vendor

Cross-site scripting (XSS) vulnerability in codebase/spreadsheet.php in the Spreadsheet (dhtmlxSpreadsheet) pl...