CVE-2025-66519 Overview
CVE-2025-66519 is a stored cross-site scripting (XSS) vulnerability in Foxit PDF Editor Cloud at pdfonline.foxit.com. The flaw resides in the Layer Import functionality. An attacker can inject a crafted payload into the Create new Layer field during layer import. The application later renders that value into the Document Object Model (DOM) without proper sanitization. When another user opens the Layers panel, the injected script executes in their browser session.
The issue is classified under CWE-79: Improper Neutralization of Input During Web Page Generation. Exploitation requires an authenticated user with low privileges and interaction from a victim who opens the Layers panel.
Critical Impact
Attackers can execute arbitrary JavaScript in the browser context of any user who opens the crafted PDF's Layers panel, enabling session token theft, cross-tenant actions in the cloud editor, and phishing pivots.
Affected Products
- Foxit PDF Editor Cloud (pdfonline.foxit.com) — Layer Import functionality
- Foxit pdf_editor_cloud (all versions prior to vendor remediation)
- Documents processed through the cloud editor's Layers panel
Discovery Timeline
- 2025-12-19 - CVE-2025-66519 published to the National Vulnerability Database (NVD)
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-66519
Vulnerability Analysis
The vulnerability sits in the layer-import workflow of Foxit's browser-based PDF editor. When a user imports a layer, the client accepts a name from the Create new Layer input. That value is persisted with the document and later injected into the Layers panel markup. The rendering path does not encode HTML control characters or strip active content before insertion into the DOM.
Because the payload is stored server-side with the document, this is a persistent XSS rather than a reflected one. Any user who opens the affected document and expands the Layers panel triggers execution. The scope metric indicates the impact crosses a trust boundary. A payload authored by a low-privilege collaborator can therefore execute in the context of a document owner or another tenant user viewing the shared file.
Root Cause
The root cause is missing output encoding on user-controlled layer metadata. The Create new Layer field accepts arbitrary strings, including HTML tags and JavaScript event handlers. The Layers panel renderer treats the stored string as trusted markup and inserts it directly into the DOM through an unsafe sink such as innerHTML. Neither server-side input validation nor client-side contextual escaping neutralizes the payload before rendering.
Attack Vector
An authenticated attacker creates or edits a PDF in Foxit PDF Editor Cloud and initiates a layer import. In the Create new Layer name field, the attacker supplies a payload containing an HTML element with a JavaScript event handler, for example an <img> tag with an onerror attribute or a <svg> tag with an inline handler. The attacker saves the document and shares it with a target or waits for a collaborator to open it.
When the victim opens the Layers panel, the browser parses the injected markup and executes the script under the origin pdfonline.foxit.com. The script can read session cookies scoped to the origin, exfiltrate document contents accessible to the victim, perform actions on behalf of the victim through the editor's authenticated APIs, or redirect the victim to attacker-controlled infrastructure. No verified proof-of-concept code has been published for this issue.
Detection Methods for CVE-2025-66519
Indicators of Compromise
- Stored PDF documents whose layer metadata contains HTML tags, JavaScript URIs, or event-handler attributes such as onerror, onload, or onclick.
- Outbound browser requests from pdfonline.foxit.com sessions to unfamiliar third-party domains immediately after users open a shared document.
- Anomalous session-cookie usage from IP addresses that do not match the legitimate user's typical geolocation.
Detection Strategies
- Inspect stored PDF layer names and metadata for HTML control characters (<, >, ", ') and JavaScript sinks before rendering.
- Enable Content Security Policy (CSP) reporting on the cloud editor origin and monitor script-src and inline-event-handler violation reports.
- Correlate document-open events with subsequent DOM-based network activity to identify script execution triggered by the Layers panel.
Monitoring Recommendations
- Log every layer-import action with the raw layer-name value and the acting user identity for forensic review.
- Alert on session-token use from new user-agent or IP combinations shortly after a shared document is opened.
- Track help-desk reports of unexpected redirects, credential prompts, or errors when users interact with the Layers panel.
How to Mitigate CVE-2025-66519
Immediate Actions Required
- Review the Foxit Security Bulletins and apply the vendor's fix for Foxit PDF Editor Cloud as soon as it is published for your tenant.
- Audit recently imported or shared PDFs for suspicious layer names containing HTML or script fragments and quarantine offending documents.
- Rotate authentication tokens and session cookies for users who opened untrusted shared documents in the affected window.
Patch Information
Foxit tracks fixes for pdf_editor_cloud through its central advisory portal. Refer to the Foxit Security Bulletins page for the specific build or service-side remediation addressing CVE-2025-66519. Because Foxit PDF Editor Cloud is a hosted service, remediation is delivered server-side by the vendor and does not require a client update. Confirm remediation by re-testing the Layer Import field against a benign HTML payload in a controlled account.
Workarounds
- Restrict Foxit PDF Editor Cloud sharing to trusted internal users until the vendor confirms the fix is deployed to your tenant.
- Instruct users to avoid opening the Layers panel on documents received from external or untrusted sources.
- Enforce a strict Content Security Policy at the browser or enterprise-proxy layer to block inline script execution on pdfonline.foxit.com.
- Use browser isolation or a dedicated browser profile for handling untrusted PDF collaborations to contain any script execution.
# Configuration example
# Example enterprise CSP override for pdfonline.foxit.com via a forward proxy
# Blocks inline handlers and constrains script sources.
Content-Security-Policy: default-src 'self' https://pdfonline.foxit.com; \
script-src 'self' https://pdfonline.foxit.com; \
object-src 'none'; base-uri 'none'; frame-ancestors 'self'
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
