DHTMLX Patches Path Traversal and RCE Flaws
CERT Polska coordinated disclosure of three DHTMLX vulnerabilities, including an unauthenticated RCE in the PDF Export Module, now patched.
CERT Polska disclosed three vulnerabilities affecting DHTMLX software components used for diagramming, Gantt charts, and scheduling. Two of the flaws (CVE-2026-7182 and CVE-2026-41552) are path traversal issues in the Diagram export module and PDF Export Module respectively, stemming from insufficient HTML sanitization of the src attribute, allowing an unauthenticated user to embed local server files into generated PDFs. The third and most serious issue, CVE-2026-41553, is a remote code execution vulnerability in the PDF Export Module used by DHTMLX's Gantt and Scheduler products, caused by a lack of sanitization on a data parameter that is processed and executed by Node.js, potentially allowing full server compromise by an unauthenticated attacker.
All three vulnerabilities were responsibly disclosed by researchers Łukasz Jaworski and Tomasz Holeksa of Pentest Limited and coordinated through CERT Polska's CVD process. Vendor fixes are available: Diagram version 1.1.1 resolves CVE-2026-7182, and PDF Export Module version 0.7.6 addresses both CVE-2026-41552 and CVE-2026-41553. No evidence of active exploitation is mentioned in the advisory; this is a coordinated disclosure with patches already released.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/05/CVE-2026-7182
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free