CVE-2026-57532
概要

Malicious HTML content contained in the layout specification of a PDF
ticket or badge layout was executed when the PDF editor is opened in the
browser. This could allow one backend user to inject JavaScript into
the browser context of another backend user. Due to requirements of the
PDF rendering and editing libraries used, this is one of the few pages
in our backend that do not have a strong Content-Security-Policy that
would render this capability useless for most scenarios.

公表日 2026年6月26日0:16
登録日 2026年6月27日4:29
最終更新日 2026年6月26日1:16
関連情報、対策とツール
共通脆弱性一覧