CVE-2026-40505 Details
Description
MuPDF before 1.27 contains an ANSI injection vulnerability in mutool that allows attackers to inject arbitrary ANSI escape sequences through crafted PDF metadata fields. Attackers can embed malicious ANSI escape codes in PDF metadata that are passed unsanitized to terminal output when running mutool info, enabling them to manipulate terminal display for social engineering attacks such as presenting fake prompts or spoofed commands.
A vulnerability exists in MuPDF's command-line tool, mutool, which fails to properly sanitize PDF metadata before it is output to the terminal. This oversight allows attackers to inject arbitrary ANSI escape sequences through manipulated PDF metadata. When the 'mutool info' command is executed, these malicious ANSI codes are transmitted unsanitized to the terminal. This could enable attackers to clear the terminal screen and display misleading text, potentially for social engineering purposes, such as creating fake prompts or impersonating commands.
Users are advised to update to the latest version of MuPDF, where this vulnerability has been addressed. The patch is available in the official MuPDF repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 16, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-150 | Improper Neutralization of Escape, Meta, or Control Sequences | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| artifex mupdf | < 1.27.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 26, 2026 | Initial Analysis | [email protected] |
| Apr 17, 2026 | CVE Modified | [email protected] |
| Apr 16, 2026 | New CVE Received | [email protected] |