A vulnerability has been found in pandora-analysis Pandora up to 1.12.5 and classified as problematic. Affected by this vulnerability is the function send_file of the component PDF Download. The manipulation leads to cross site scripting.

This vulnerability is uniquely identified as CVE-2026-75529. The attack is possible to be carried out remotely. No exploit exists.

It is suggested to install a patch to address this issue.