
🚨Critical - DHTMLX PDF Export Module Critical RCE + Path Traversal (CVE-2026-41552 & CVE-2026-41553) The PDF Export Module used in DHTMLX Gantt, Scheduler and other products contains two critical vulnerabilities: CVE-2026-41553: Lack of sanitization on the "data" parameter allows unauthenticated Remote Code Execution (OS Command Injection) via Node.js. CVE-2026-41552: Path Traversal allows unauthenticated attackers to read arbitrary files on the server and include them in generated PDFs. 👉Affected: PDF Export Module < 0.7.6
Post summary
The post announces critical Remote Code Execution and Path Traversal vulnerabilities (CVE-2026-41552 and CVE-2026-41553) in the DHTMLX PDF Export Module for versions below 0.7.6, detailing the affected parameters and potential impacts.
