Article Summary:

A security vulnerability (CVE-2025-53367) has been discovered in the DJVU library, a popular open-source tool used for creating, converting, and reading .djvu files. The issue is an out-of-bounds write vulnerability that can potentially lead to arbitrary code execution when handling maliciously crafted .djvu files. This matters significantly as it could pose a threat to developers using the DJVU library in their projects or end-users dealing with .djvu files. To mitigate this risk, it is recommended to update to the latest version of the library that addresses this vulnerability.

Learn more: https://github.blog/security/vulnerability-research/cve-2025-53367-an-exploitable-out-of-bounds-write-in-djvulibre/