HIGH🇵🇱 Wersja polska

CVE-2026-25755

CVSS 8.1v3.1pub. 2026-02-19upd. 2026-08-18

jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of the argument of the `addJS` method allows an attacker to inject arbitrary PDF objects into the generated document. By crafting a payload that escapes the JavaScript string delimiter, an attacker can execute malicious actions or alter the document structure, impacting any user who opens the generated PDF. The vulnerability has been fixed in jspdf@4.2.0. As a workaround, escape parentheses in user-provided JavaScript code before passing them to the `addJS` method.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
  • Parall Jspdf

    APP
    Parall
    < 4.2.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-31938CRITICAL9.6PL ✓same product

XSS w bibliotece jsPDF — wstrzyknięcie skryptów przez argument output()

CVE-2025-68428CRITICAL9.2PL ✓same product

Path traversal w jsPDF (Node.js) umożliwia odczyt dowolnych plików

CVE-2026-31898HIGH8.1same product

jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of arguments of the `c...

CVE-2026-25535HIGH8.7same product

jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of the first argument of the `...

CVE-2026-25940HIGH8.1same product

jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of properties and methods of t...