
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-59803 is a signature spoofing vulnerability in Foxit PDF Editor and Reader that allows attackers to embed triggers (e.g., JavaScript) in PDF documents that execute during the signing process, causing the signed document to differ from what the signer reviewed. The vulnerability affects Foxit PDF Editor and Reader before versions 2025.2.1, 14.0.1, and 13.2.1. It was published on December 11, 2025, and carries a CVSS v3.1 base score of 5.3 (Medium), classified under CWE-347 (Improper Verification of Cryptographic Signature) (Red Hat CVE, Foxit Security Bulletins).
The root cause is classified as CWE-347 (Improper Verification of Cryptographic Signature), where Foxit PDF Editor and Reader fail to prevent embedded triggers — such as JavaScript actions — from modifying document content during or after the signing process. An attacker crafts a malicious PDF containing triggers tied to signing events; when a signer opens and reviews the document, the content appears legitimate, but upon applying the digital signature, the triggers silently alter content on other pages or within optional content layers (OCGs) without any explicit warning to the signer. This results in the cryptographically signed document containing content that was never reviewed or approved by the signer. The attack requires no privileges but does require user interaction (the victim must open and sign the crafted PDF) (Red Hat CVE, Foxit Security Bulletins).
Successful exploitation undermines the integrity and trustworthiness of digital signatures in PDF documents, as the signed content can differ materially from what the signer reviewed and intended to approve. This can lead to unauthorized document modifications, falsification of legally or contractually binding signed documents, and compromised document verification processes. There is no confidentiality or availability impact; the primary risk is to document integrity in workflows that rely on Foxit-generated digital signatures (Red Hat CVE).
/AA, /OpenAction, /AA /O, /AA /C dictionary entries) associated with page or field events that reference content modification functions.pdfid, pdf-parser).Foxit has released patched versions that address this vulnerability: 2025.2.1, 14.0.1, and 13.2.1 for their respective product lines. Users should upgrade Foxit PDF Editor and Reader to one of these fixed versions immediately. As interim mitigations, organizations should disable JavaScript execution in Foxit PDF settings (Preferences > JavaScript > uncheck "Enable JavaScript Actions"), implement strict PDF review processes before signing, and exercise caution when signing PDFs received from untrusted sources (Foxit Security Bulletins).
The vulnerability received limited public attention at the time of disclosure. It was noted in automated CVE tracking feeds and patch management platforms such as Patch My PC, and was detected by Tenable Nessus plugins (IDs 266310 and 266311). No significant researcher commentary or media coverage has been identified beyond standard vulnerability database entries (Tenable Nessus).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."