Foxit PDF Editor/Reader failed to validate the directory traversal path in the attachment file name, resulting in malicious attachments being able to be written to directories outside the expected secure area when the PDF is opened.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-91797 represents a critical path traversal vulnerability in Foxit PDF Editor and Reader that bypasses attachment filename validation. When a user opens a malicious PDF containing specially crafted attachment filenames, the application fails to sanitize directory traversal sequences (such as '../'), allowing attackers to write files to arbitrary locations on the victim's system outside the intended secure attachment directory. This vulnerability affects millions of users who rely on Foxit as a primary PDF reader, and the ability to write files to arbitrary locations enables multiple attack chains including code execution, privilege escalation, or persistence mechanisms. The high CVSS score of 7.8 reflects the severity of unrestricted file write capabilities combined with the widespread adoption of PDF readers as trusted applications.
While this CVE currently shows zero matching Casky skills due to its novelty and the lack of mapped MITRE ATT&CK techniques in the disclosure, Casky's Claude AI with extended reasoning capabilities would detect related attack patterns across the 754 mapped security skills through behavioral analysis of file system operations and attachment processing. Practitioners using Casky would observe findings related to CWE-73 (External Control of File Name or Path) patterns, file write anomalies in unexpected system directories, and suspicious attachment handling workflows. As security teams map this CVE to defensive controls, Claude's reasoning engine would correlate this vulnerability with techniques like T1566 (Phishing - Attachment), T1204 (User Execution), and T1547 (Boot or Logon Autostart Execution) if weaponized for persistence, enabling practitioners to develop comprehensive detection strategies even for zero-day or newly disclosed vulnerabilities.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-91797. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation