CVE-2024-4367Active Exploitation(debian / debian_linux)

MEDIUMCVSS 8.8 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch debian debian_linux systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.

5.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-754

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • debian_linux
  • firefox
  • open-xchange_appsuite_frontend
  • thunderbird

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 5 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 4d ago at 1 mentions (2026-02-02); latest day: 1
  • 5 total mentions across 5 days

Affected systems

Products
debian_linuxfirefoxopen-xchange_appsuite_frontendthunderbird

2 versions affected across 4 products

Deep dive

Activity timeline5 mentions / 5d
00111Mentions · 2026-02-02: 1Mentions · 2026-04-02: 1Mentions · 2026-06-20: 1Mentions · 2026-09-13: 1Mentions · 2026-09-24: 1Active Exploitation · 2026-04-02: 1Active Exploitation · 2026-06-20: 1Patch / Workaround · 2026-04-02: 1Patch / Workaround · 2026-09-24: 1Technical Details · 2026-04-02: 1Technical Details · 2026-09-13: 102-0204-0206-2009-1309-24
Signal classification4 categories
Active Exploitation
240.0%
General
120.0%
Disclosure
120.0%
Patch
120.0%
Referenced assets1 URL
Classification over time
DateTotalLabels
2026-02-021
General1
2026-04-021
Active Exploitation1
2026-06-201
Active Exploitation1
2026-09-131
Disclosure1
2026-09-241
Patch1
Full discourse5 posts
  • Coffin@lostsec_
    Disclosure

    more detail: https://infosecwriteups.com/pdf-js-arbitrary-javascript-code-execution-cve-2024-4367-be4a64f877df?sk=19cadb705d4e9f5d738a62d4e52ba8ec

    Post summary

    The text contains only a link to an article about CVE-2024-4367 (PDF.js arbitrary JavaScript code execution) with no PoC, exploit tool, patch, or exploitation evidence provided in the text itself.

    110971.1K
    32.1K followersView on X
  • flexinz@flexinz_
    General

    CVE-2024-4367 detected

    Post summary

    The snippet merely notes detection of CVE-2024-4367 without additional context.

    10060702
    686 followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    CVE-2024-4367 (CVSS 8.8) in PDF.js allows arbitrary JavaScript execution via malicious FontMatrix values in PDFs. Still widely exploitable in 2026 due to AI-generated code using vulnerable versions. Upgrade to 4.2.67+ or disable isEvalSupported. #DFIR_Radar https://t.co/YgnDCH5AlP

    Post summary

    The tweet reports that CVE‑2024‑4367 in PDF.js remains widely exploitable in 2026, gives a CVSS score, and recommends upgrading or disabling isEvalSupported.

    12021237
    1.7K followersView on X
  • Michael Kaiser@MichaelKaiserAI
    Patch

    Day 15 &amp; 16 of building in public. 48h open-source sprint: • open-pdf-signer: Added real CMS/PKCS#7 crypto signing &amp; CVE-2024-4367 fix • agent-loops: Runner hardening, trust boundaries &amp; parity tests Production-grade code. Back to building.

    Post summary

    The post primarily announces that a fix for CVE-2024-4367 was added to open-pdf-signer during an open-source sprint. It provides patch-oriented information but lacks PoC, exploit, active exploitation, or detailed vulnerability analysis.

    2002076
    34 followersView on X
  • Omh@OmhCrl
    Active Exploitation

    @RamjiSingh10078 @yeswehack Hi! It was execution of CVE-2024-4367

    Post summary

    A user reports having observed execution of CVE-2024-4367, suggesting active exploitation with no supporting details.

    00012121
    250 followersView on X
CPE platform detail48 entries

48 of 48 entries

PartVendorProductVersionTarget SWTarget HW
OSdebiandebian_linux10.0--
Appmozillafirefox---
Appmozillafirefox---
Appmozillathunderbird---
Appopen-xchangeopen-xchange_appsuite_frontend---
Appopen-xchangeopen-xchange_appsuite_frontend7.10.6--
Appopen-xchangeopen-xchange_appsuite_frontend7.10.6--
Appopen-xchangeopen-xchange_appsuite_frontend7.10.6--
Appopen-xchangeopen-xchange_appsuite_frontend7.10.6--
Appopen-xchangeopen-xchange_appsuite_frontend7.10.6--
Appopen-xchangeopen-xchange_appsuite_frontend7.10.6--
Appopen-xchangeopen-xchange_appsuite_frontend7.10.6--
Appopen-xchangeopen-xchange_appsuite_frontend7.10.6--
Appopen-xchangeopen-xchange_appsuite_frontend7.10.6--
Appopen-xchangeopen-xchange_appsuite_frontend7.10.6--
Appopen-xchangeopen-xchange_appsuite_frontend7.10.6--
Appopen-xchangeopen-xchange_appsuite_frontend7.10.6--
Appopen-xchangeopen-xchange_appsuite_frontend7.10.6--
Appopen-xchangeopen-xchange_appsuite_frontend7.10.6--
Appopen-xchangeopen-xchange_appsuite_frontend7.10.6--
Appopen-xchangeopen-xchange_appsuite_frontend7.10.6--
Appopen-xchangeopen-xchange_appsuite_frontend7.10.6--
Appopen-xchangeopen-xchange_appsuite_frontend7.10.6--
Appopen-xchangeopen-xchange_appsuite_frontend7.10.6--
Appopen-xchangeopen-xchange_appsuite_frontend7.10.6--
Appopen-xchangeopen-xchange_appsuite_frontend7.10.6--
Appopen-xchangeopen-xchange_appsuite_frontend7.10.6--
Appopen-xchangeopen-xchange_appsuite_frontend7.10.6--
Appopen-xchangeopen-xchange_appsuite_frontend7.10.6--
Appopen-xchangeopen-xchange_appsuite_frontend7.10.6--
Appopen-xchangeopen-xchange_appsuite_frontend7.10.6--
Appopen-xchangeopen-xchange_appsuite_frontend7.10.6--
Appopen-xchangeopen-xchange_appsuite_frontend7.10.6--
Appopen-xchangeopen-xchange_appsuite_frontend7.10.6--
Appopen-xchangeopen-xchange_appsuite_frontend7.10.6--
Appopen-xchangeopen-xchange_appsuite_frontend7.10.6--
Appopen-xchangeopen-xchange_appsuite_frontend7.10.6--
Appopen-xchangeopen-xchange_appsuite_frontend7.10.6--
Appopen-xchangeopen-xchange_appsuite_frontend7.10.6--
Appopen-xchangeopen-xchange_appsuite_frontend7.10.6--
Appopen-xchangeopen-xchange_appsuite_frontend7.10.6--
Appopen-xchangeopen-xchange_appsuite_frontend7.10.6--
Appopen-xchangeopen-xchange_appsuite_frontend7.10.6--
Appopen-xchangeopen-xchange_appsuite_frontend7.10.6--
Appopen-xchangeopen-xchange_appsuite_frontend7.10.6--
Appopen-xchangeopen-xchange_appsuite_frontend7.10.6--
Appopen-xchangeopen-xchange_appsuite_frontend7.10.6--
Appopen-xchangeopen-xchange_appsuite_frontend7.10.6--

Explore more