Skip to main content
HIGH

CVE-2019-1000005

CVSS v3

8.8

HIGH

EPSS Score

2.1 %

exploit probability, as of 2026-09-25

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

mPDF version 7.1.7 and earlier contains a CWE-502: Deserialization of Untrusted Data vulnerability in getImage() method of Image/ImageProcessor class that can result in Arbitry code execution, file write, etc.. This attack appears to be exploitable via attacker must host crafted image on victim server and trigger generation of pdf file with content <img src="phar://path/to/crafted/image">. This vulnerability appears to have been fixed in 7.1.8.

Technical details

Published
2019-02-04

Frequently asked questions

What is CVE-2019-1000005?

mPDF version 7.1.7 and earlier contains a CWE-502: Deserialization of Untrusted Data vulnerability in getImage() method of Image/ImageProcessor class that can result in Arbitry code execution, file write, etc.. This attack appears to be exploitable via attacker must host crafted image on victim server and trigger generation of pdf file with content <img src="phar://path/to/crafted/image">. This vulnerability appears to have been fixed in 7.1.8.

Is CVE-2019-1000005 actively exploited?

Active exploitation of CVE-2019-1000005 has not been confirmed. Its EPSS score was 2.1% on 2026-09-25, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2019-1000005?

CVE-2019-1000005 has a CVSS v3 base score of 8.8 (HIGH severity).

Is CVE-2019-1000005 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key