
CVE-2026-40505 MuPDF mutool does not sanitize PDF metadata fields before writing them to terminal output, allowing attackers to inject arbitrary ANSI escape sequences through crafte… https://www.cve.org/CVERecord?id=CVE-2026-40505
Post summary
This post announces a sanitization flaw in MuPDF mutool that permits injection of arbitrary ANSI escape sequences via PDF metadata.

