PT-2025-7781 · Tex Live+2 · Tex Live+2

Vicevirus

·

Published

2025-02-18

·

Updated

2025-11-27

·

CVE-2025-26525

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions TeX Live (affected versions not specified)
Description The issue is related to insufficient sanitizing in the TeX notation filter, which poses an arbitrary file read risk on sites where pdfTeX is available. This typically affects systems with TeX Live installed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Files Accessible to External Parties

Weakness Enumeration

Related Identifiers

ALT-PU-2025-6924
ALT-PU-2025-7344
BDU:2025-02323
BIT-MOODLE-2025-26525
CVE-2025-26525
GHSA-4HMR-39VP-XFRR

Affected Products

Alt Linux
Red Os
Tex Live