
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14420 is a directory traversal vulnerability in pdfforge PDF Architect that enables remote attackers to execute arbitrary code on affected installations. The flaw resides in the parsing of CBZ (Comic Book ZIP) files, where user-supplied path values are not properly validated before being used in file operations. It was reported to the vendor on August 12, 2025, and publicly disclosed as a zero-day advisory on December 11, 2025, after the vendor did not respond to multiple follow-ups. The affected version is PDF Architect 9.1.74.23030, and the vulnerability carries a CVSS v3.0 base score of 7.8 (High) (ZDI Advisory).
The root cause is improper limitation of a pathname to a restricted directory (CWE-22 / Path Traversal). When PDF Architect parses a CBZ file — which is essentially a ZIP archive — it fails to sanitize embedded file paths before performing file system operations, allowing an attacker to write files to arbitrary locations outside the intended directory. Exploitation requires the target user to open a specially crafted malicious CBZ file or visit a page that triggers its processing. The vulnerability was tracked internally by ZDI as ZDI-CAN-27514 and credited to researcher kimiya (ZDI Advisory).
Successful exploitation allows an attacker to execute arbitrary code in the context of the currently logged-in user, resulting in high confidentiality, integrity, and availability impact. An attacker could write malicious files to sensitive locations (e.g., startup folders, application directories) to achieve persistence or escalate privileges, and could access or exfiltrate data accessible to the user. The scope is limited to the local system of the victim, but lateral movement is possible if the compromised user account has network access or elevated privileges (ZDI Advisory).
This vulnerability was published as a zero-day advisory on December 11, 2025, meaning no vendor patch was available at the time of disclosure. No public proof-of-concept exploit code has been identified, and there is no evidence of in-the-wild exploitation or threat actor attribution at this time. The EPSS score is approximately 0.119%, indicating a low probability of near-term exploitation, and it is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires user interaction — the victim must open a malicious CBZ file — which somewhat limits the attack surface (ZDI Advisory, Feedly).
.cbz extension) containing a file with a path-traversal sequence in its filename, such as ../../AppData/Roaming/Microsoft/Windows/Start Menu/Programs/Startup/malicious.exe, embedding a malicious executable payload.%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\, %TEMP%, or application directories; newly created executables or scripts with unusual names in user-writable locations.cmd.exe, powershell.exe, or unknown executables); PDF Architect process accessing file paths containing ..\ or ../ sequences.As of the zero-day disclosure date (December 11, 2025), no vendor patch was available; ZDI noted that the vendor did not provide a fix despite coordinated disclosure attempts beginning August 12, 2025. ZDI's recommended mitigation is to restrict interaction with PDF Architect, particularly avoiding opening CBZ files from untrusted sources. Users should apply the principle of least privilege to limit the impact of potential exploitation, and organizations should monitor for and block delivery of unsolicited CBZ files via email gateways. Users are advised to check pdfforge's official channels for any subsequent patch releases (ZDI Advisory).
The vulnerability was disclosed by the Zero Day Initiative (Trend Micro) as a zero-day after the vendor failed to respond adequately to multiple follow-up attempts over four months. The ZDI disclosure timeline highlights a breakdown in coordinated disclosure, with ZDI notifying pdfforge of its intent to publish before receiving a patch. No significant public commentary from the broader security community or media coverage beyond standard vulnerability database aggregation has been identified (ZDI Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."