CVE-2026-41553
Published: 15 May 2026
Summary
CVE-2026-41553 is a critical-severity OS Command Injection (CWE-78) vulnerability in Dhtmlx Pdf Export Module. Its CVSS base score is 10.0 (Critical).
Operationally, ranked at the 48.7th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
Threat & Defense Details
Likely Mitigating ControlsAI
Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.
NVD Description
PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Remote Code Execution due to lack of "data" parameter sanitization. An unauthenticated attacker can inject the malicious JavaScript code to the parameter whose value is processed by…
more
Node.js and subsequently executed. This can lead to server compromise. This issue was fixed in PDF Export Module version 0.7.6.
Deeper analysisAI
Automated synthesis unavailable for this CVE.
Details
- CWE(s)