Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2024-4367-hands-on — Hands-on lab to learn CVE-2024-4367 (Firefox PDF.js RCE) with PoC generation, vulnerable browser launch, and patched version verification. | Kitploit
Tools/GitHubGitHub/penguincabinet/cve-2024-4367-hands-on
Vulnerability AnalysisExploitationWeb Application ExploitationLearning & EducationLabs & Practice
GitHubpenguincabinet/cve-2024-4367-hands-on

CVE-2024-4367-hands-on

Hands-on lab to learn CVE-2024-4367 (Firefox PDF.js RCE) with PoC generation, vulnerable browser launch, and patched version verification.

View Repository
21 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

[!IMPORTANT] This repository is for learning about vulnerabilities.
This hands-on must be performed on a computer you properly manage. Do not engage in any illegal activities.
The author assumes no responsibility for any damages or liabilities arising from this repository.

CVE-2024-4367-hands-on

Hands-on experience with CVE-2024-4367

Creating poc.pdf

python CVE-2024-4367-PoC/CVE-2024-4367.py "alert('document.domain')"

Source: https://github.com/LOURC0D3/CVE-2024-4367-PoC

An attack poc.pdf will be created.
For detailed usage, please refer to the following:
https://github.com/LOURC0D3/CVE-2024-4367-PoC

Launch a vulnerable Firefox and confirm the attack

python firefox.py 125

Open poc.pdf using a vulnerable version of Firefox Nightly.
The first launch will take time because it downloads Firefox Nightly.
Confirm that JavaScript executes and an alert is displayed.

Verify with a patched Firefox

python firefox.py 135

Open poc.pdf with a newer version of Firefox Nightly, confirm that no alert is displayed, and that the vulnerability has been patched.

Compare PDF.js source code

There is vulnerable-pdf.js containing the vulnerability and invulnerable-pdf.js with the fix.

pdfjs_diff_font_renderer.js is the diff between vulnerable-pdf.js/src/core/font_renderer.js and invulnerable-pdf.js/src/core/font_renderer.js.

Download Tool