CVE-2025-26525 HIGH

CVE-2025-26525: Arbitrary file read risk through pdfTeX

Vendor Moodle Project
Product moodle
Weakness CWE-552 · Files accessible externally
Published February 24, 2025
Last update February 24, 2025

CVSS base score

8.6/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

What the vulnerability does

01Description

Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is available (such as those with TeX Live installed).

Key dates

02Disclosure timeline

February 24, 2025 CVE published
February 24, 2025 Record updated