CVE-2025-59803
Foxit PDF Reader vulnerability analysis and mitigation

Overview

CVE-2025-59803 is a signature spoofing vulnerability in Foxit PDF Editor and Reader that allows attackers to embed triggers (e.g., JavaScript) in PDF documents that execute during the signing process, causing the signed document to differ from what the signer reviewed. The vulnerability affects Foxit PDF Editor and Reader before versions 2025.2.1, 14.0.1, and 13.2.1. It was published on December 11, 2025, and carries a CVSS v3.1 base score of 5.3 (Medium), classified under CWE-347 (Improper Verification of Cryptographic Signature) (Red Hat CVE, Foxit Security Bulletins).

Technical details

The root cause is classified as CWE-347 (Improper Verification of Cryptographic Signature), where Foxit PDF Editor and Reader fail to prevent embedded triggers — such as JavaScript actions — from modifying document content during or after the signing process. An attacker crafts a malicious PDF containing triggers tied to signing events; when a signer opens and reviews the document, the content appears legitimate, but upon applying the digital signature, the triggers silently alter content on other pages or within optional content layers (OCGs) without any explicit warning to the signer. This results in the cryptographically signed document containing content that was never reviewed or approved by the signer. The attack requires no privileges but does require user interaction (the victim must open and sign the crafted PDF) (Red Hat CVE, Foxit Security Bulletins).

Impact

Successful exploitation undermines the integrity and trustworthiness of digital signatures in PDF documents, as the signed content can differ materially from what the signer reviewed and intended to approve. This can lead to unauthorized document modifications, falsification of legally or contractually binding signed documents, and compromised document verification processes. There is no confidentiality or availability impact; the primary risk is to document integrity in workflows that rely on Foxit-generated digital signatures (Red Hat CVE).

Exploitation steps

  1. Craft malicious PDF: Create a PDF document with embedded JavaScript or other trigger actions (e.g., page open/close events, form field triggers) that are designed to activate during the signing workflow, modifying content on alternate pages or toggling optional content layers.
  2. Social engineering delivery: Deliver the crafted PDF to a target signer via email, file share, or other means, presenting it as a legitimate document requiring a digital signature.
  3. Victim reviews document: The signer opens the PDF in a vulnerable version of Foxit PDF Editor or Reader; the document appears normal and unmodified during review.
  4. Signature applied: The signer applies their digital signature; at this point, the embedded triggers execute silently, altering document content (e.g., changing text, revealing hidden layers, modifying other pages) without any warning dialog.
  5. Signed document distributed: The attacker retrieves or receives the now-signed PDF, which contains the attacker's modified content bearing the victim's valid digital signature, potentially for use in fraud, contract manipulation, or other deceptive purposes (Foxit Security Bulletins, Red Hat CVE).

Indicators of compromise

  • File System: PDF files containing JavaScript actions or trigger events (e.g., /AA, /OpenAction, /AA /O, /AA /C dictionary entries) associated with page or field events that reference content modification functions.
  • File System: PDFs with Optional Content Groups (OCGs) that are toggled by JavaScript during signing events — detectable via PDF analysis tools (e.g., pdfid, pdf-parser).
  • Logs: Foxit application logs showing JavaScript execution events triggered during the document signing workflow.
  • Process: Unexpected JavaScript execution within Foxit PDF Editor/Reader processes at the time a digital signature is applied to a document.

Mitigation and workarounds

Foxit has released patched versions that address this vulnerability: 2025.2.1, 14.0.1, and 13.2.1 for their respective product lines. Users should upgrade Foxit PDF Editor and Reader to one of these fixed versions immediately. As interim mitigations, organizations should disable JavaScript execution in Foxit PDF settings (Preferences > JavaScript > uncheck "Enable JavaScript Actions"), implement strict PDF review processes before signing, and exercise caution when signing PDFs received from untrusted sources (Foxit Security Bulletins).

Community reactions

The vulnerability received limited public attention at the time of disclosure. It was noted in automated CVE tracking feeds and patch management platforms such as Patch My PC, and was detected by Tenable Nessus plugins (IDs 266310 and 266311). No significant researcher commentary or media coverage has been identified beyond standard vulnerability database entries (Tenable Nessus).

Additional resources


SourceThis report was generated using AI

Related Foxit PDF Reader vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-57260HIGH7.8
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57256HIGH7.8
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57259MEDIUM6.5
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57258MEDIUM6.1
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57257MEDIUM6.1
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management