PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Remote Code Execution due to lack of "data" parameter sanitization. An unauthenticated attacker can inject the malicious JavaScript code to the parameter whose value is processed by Node.js and subsequently executed. This can lead to server compromise. This issue was fixed in PDF Export Module version 0.7.6.
History

Sun, 17 May 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Dhtmlx
Dhtmlx pdf Export Module
Vendors & Products Dhtmlx
Dhtmlx pdf Export Module

Fri, 15 May 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 15 May 2026 13:00:00 +0000

Type Values Removed Values Added
Description PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Remote Code Execution due to lack of "data" parameter sanitization. An unauthenticated attacker can inject the malicious JavaScript code to the parameter whose value is processed by Node.js and subsequently executed. This can lead to server compromise. This issue was fixed in PDF Export Module version 0.7.6.
Title Remote Code Execution in PDF Export Module
Weaknesses CWE-78
References
Metrics cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published: 2026-05-15T12:31:30.195Z

Updated: 2026-05-15T13:13:14.917Z

Reserved: 2026-04-21T12:09:57.293Z

Link: CVE-2026-41553

cve-icon Vulnrichment

Updated: 2026-05-15T13:13:11.469Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-05-15T13:16:19.130

Modified: 2026-05-15T14:12:43.710

Link: CVE-2026-41553

cve-icon Redhat

No data.