
🚨Critical - DHTMLX PDF Export Module Critical RCE + Path Traversal (CVE-2026-41552 & CVE-2026-41553) The PDF Export Module used in DHTMLX Gantt, Scheduler and other products contains two critical vulnerabilities: CVE-2026-41553: Lack of sanitization on the "data" parameter allows unauthenticated Remote Code Execution (OS Command Injection) via Node.js. CVE-2026-41552: Path Traversal allows unauthenticated attackers to read arbitrary files on the server and include them in generated PDFs. 👉Affected: PDF Export Module < 0.7.6
Post summary
The passage announces two critical vulnerabilities (CVE-2026-41552 & CVE-2026-41553) in the DHTMLX PDF Export Module, detailing RCE and path traversal issues, but offers no proof‑of‑concept, exploit code, or patch information.
