CVE-2025-14413
HIGH 7.8Soda PDF Desktop CBZ File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Soda PDF Desktop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the parsing of CBZ files. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-27509.
Affected Applications in Environment
12
Desktop
v4.67.0 (4.67.0.5)
2 devices
Desktop
v4.41.2 (4.41.2.20)
2 devices
Desktop
v4.62.0 (4.62.0.11)
2 devices
Desktop
v4.63.0 (4.63.0.11)
3 devices
Desktop
v4.66.0 (4.66.0.6)
4 devices
Desktop
v4.64.0 (4.64.0.4)
3 devices
Desktop
v4.53.0 (4.52.0.4)
1 device
Desktop
v4.65.0 (4.65.0.4)
4 devices
Desktop
v4.50.0 (4.50.0.5)
1 device
Desktop
v4.66.1 (4.66.1.8)
3 devices
Desktop
v4.61.0 (4.61.0.14)
1 device
Desktop
v4.49.0 (4.49.0.17)
1 device
Affected Devices
16
Dallins-MacBook-Pro-2.local
Mac
F-16
Mac
RobertsMacbookPro.local
Mac
Zhiyuns-MacBook-Pro.local
Mac
a00288946-F6VM65M2H3
Mac
a00295943-YF4WY76Q4D
Mac
a00957369-K6KVHY00C5
Mac
a01513577-M7GJNF6XQR
Mac
a01841079-LK4T0Y7FP4
Mac
a01875599-TY6TF9Y69L
Mac
a02273884-FYQGVQ1TFP
Mac
a02490072-PCVFY9PJV6
Mac
adamthomas-H73N967GM2
Mac
admin.integrations's iMac -H12CRHNTJV40
Mac
ah-mbp.lan
Mac
ken-mpb16-LG9VYFY7QD
Mac