DEBIAN-CVE-2026-40505

Source
https://security-tracker.debian.org/tracker/CVE-2026-40505
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-40505.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-40505
Upstream
Published
2026-04-16T02:16:11Z
Modified
2026-09-14T17:03:10Z
Severity
  • 4.8 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
[none]
Details

MuPDF before 1.27 contains an ANSI injection vulnerability in mutool that allows attackers to inject arbitrary ANSI escape sequences through crafted PDF metadata fields. Attackers can embed malicious ANSI escape codes in PDF metadata that are passed unsanitized to terminal output when running mutool info, enabling them to manipulate terminal display for social engineering attacks such as presenting fake prompts or spoofed commands.

References

Affected packages

Debian:12 / mupdf

Package

Name
mupdf
Purl
pkg:deb/debian/mupdf?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.21.1+ds2-1
1.21.1+ds2-1+deb12u1
1.22.1+ds1-1
1.22.2+ds1-1
1.22.2+ds1-2
1.23.6+ds1-1
1.23.7+ds1-1
1.23.10+ds1-1
1.23.10+ds1-2
1.24.3+ds1-1
1.24.8+ds2-1
1.24.8+ds2-2
1.24.9+ds1-1
1.24.10+ds1-1
1.25.1+ds1-1
1.25.1+ds1-2
1.25.1+ds1-3
1.25.1+ds1-4
1.25.1+ds1-5
1.25.1+ds1-6
1.25.1+ds1-7
1.25.1+ds1-8
1.25.1+ds1-9
1.27.0+ds1-1
1.27.0+ds1-2
1.27.0+ds1-3
1.27.0+ds1-4
1.27.0+ds1-5
1.27.0+ds1-6
1.28.0+ds1-1
1.28.2+ds1-1
1.28.2+ds1-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-40505.json"

Debian:13 / mupdf

Package

Name
mupdf
Purl
pkg:deb/debian/mupdf?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.25.1+ds1-6
1.25.1+ds1-6+deb13u1
1.25.1+ds1-7
1.25.1+ds1-8
1.25.1+ds1-9
1.27.0+ds1-1
1.27.0+ds1-2
1.27.0+ds1-3
1.27.0+ds1-4
1.27.0+ds1-5
1.27.0+ds1-6
1.28.0+ds1-1
1.28.2+ds1-1
1.28.2+ds1-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-40505.json"

Debian:14 / mupdf

Package

Name
mupdf
Purl
pkg:deb/debian/mupdf?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.27.0+ds1-5

Affected versions

1.*
1.25.1+ds1-6
1.25.1+ds1-7
1.25.1+ds1-8
1.25.1+ds1-9
1.27.0+ds1-1
1.27.0+ds1-2
1.27.0+ds1-3
1.27.0+ds1-4

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-40505.json"