CVE-2026-25925: Modery Powerdocu
High severity, CVSS 7.8. EPSS: 0.6% chance of exploitation in the next 30 days.
PowerDocu contains a Windows GUI executable to perform technical documentations. Prior to 2.4.0, PowerDocu contains a critical security vulnerability in how it parses JSON files within Flow or App packages. The application blindly trusts the $type property in JSON files, allowing an attacker to instantiate arbitrary .NET objects and execute code. This vulnerability is fixed in 2.4.0.
Affected products
- Modery Powerdocu: before 2.4.0 (fixed in 2.4.0)
Published 2026-02-09. Last modified 2026-06-17.