
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-51966 is a cross-site scripting (XSS) vulnerability in the PDF preview functionality of uTools through version 7.1.1. When a user previews a specially crafted PDF file, embedded JavaScript code executes within the application's privileged context, potentially enabling data theft or unauthorized actions. The vulnerability was published on September 2, 2025, and carries a CVSS v3.1 base score of 6.1 (Medium) (Feedly, ENISA EUVD).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting). The root cause lies in insufficient sanitization of PDF content during the preview rendering process within uTools, an Electron-based productivity application. Because the PDF preview runs in a privileged application context rather than an isolated sandbox, injected JavaScript can access application-level APIs and sensitive data. Public write-ups and proof-of-concept details are available from the researcher's blog (Researcher Blog, CVE PoC).
Successful exploitation allows an attacker to execute arbitrary JavaScript within uTools' privileged application context, bypassing typical browser-level XSS sandboxing. This can result in theft of sensitive user data accessible to the application, unauthorized actions performed on behalf of the user, and potential compromise of user sessions or confidential information stored within uTools. The CVSS scope is marked as "Changed," reflecting that the impact extends beyond the vulnerable component itself (Feedly).
Multiple proof-of-concept exploits are publicly available on GitHub Pages, published by the original researcher in May and September 2025. There is no confirmed evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The vulnerability requires user interaction — specifically, a user must preview a maliciously crafted PDF file. The EPSS score is approximately 0.028% (0.000280), indicating a currently low probability of exploitation in the wild (Feedly, Researcher Blog).
/OpenAction or /AA trigger that executes app.alert() or a data-exfiltration payload./JS, /JavaScript, /OpenAction entries detectable via PDF analysis tools).curl, powershell, cmd.exe, or shell processes) following a PDF preview action.Users should upgrade uTools to a version beyond 7.1.1, as the vendor patch addresses this vulnerability. As an interim workaround, avoid previewing PDF files received from untrusted or unknown sources within uTools. Organizations can also implement web content filtering to block delivery of potentially malicious PDF files, and restrict uTools' network access via host-based firewall rules to limit the impact of any successful exploitation (Feedly).
The vulnerability was initially disclosed by a security researcher on their GitHub Pages blog in May 2025, with a formal CVE write-up published in September 2025. Red Hat has tracked the CVE in their security advisory database. No major vendor statements or widespread media coverage have been identified beyond the researcher's own publications (Researcher Blog, Red Hat Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."