CVE-2025-69624Disclosure(gonitro / nitro_pdf_pro)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Nitro PDF Pro before 14.43 for Windows contains a NULL pointer dereference vulnerability in the JavaScript implementation of app.alert(). When app.alert() is called with more than one argument and the first argument evaluates to null (for example, app.alert(app.activeDocs, true) when app.activeDocs is null), the engine routes the call through a fallback path intended for non-string arguments. In this path, js_ValueToString() is invoked on the null value and returns an invalid string pointer, which is then passed to JS_GetStringChars() without validation. Dereferencing this pointer leads to an access violation and application crash when opening a crafted PDF. For example, 14.41.1.4 and 14.42.0.34 have been reported as vulnerable.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-476

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nitro_pdf_pro
  • windows

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Products
nitro_pdf_prowindows

2 versions affected across 2 products

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-13: 2Technical Details · 2026-04-13: 204-13
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-69624 NULL Pointer Dereference in Nitro PDF Pro 14.41.1.4 JavaScript Implementation https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-69624

    Post summary

    The post reports a NULL Pointer Dereference vulnerability (CVE-2025-69624) in Nitro PDF Pro 14.41.1.4's JavaScript engine, but provides no PoC, exploit, active exploitation evidence, or patch information.

    0000077
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-69624 Nitro PDF Pro for Windows 14.41.1.4 contains a NULL pointer dereference vulnerability in the JavaScript implementation of app.alert(). When app.alert() is called with… https://www.cve.org/CVERecord?id=CVE-2025-69624

    Post summary

    The post announces a NULL pointer dereference vulnerability in Nitro PDF Pro's JavaScript app.alert() function, linking to the CVE record without mentioning exploits, patches, or active exploitation.

    00000170
    57.1K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appgonitronitro_pdf_pro14.41.1.4--
OSmicrosoftwindows---

Explore more