📦 Jspdf

by Parall

🔍 What is Jspdf?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-25940

HIGH CVSS 8.1 Feb 19, 2026

This vulnerability in jsPDF allows attackers to inject arbitrary PDF objects, including JavaScript actions, through user-controlled properties in the Acroform module. When exploited, malicious JavaScr...

CVE-2026-25755

HIGH CVSS 8.1 Feb 19, 2026

This vulnerability in jsPDF allows attackers to inject arbitrary PDF objects into generated documents by controlling the argument of the `addJS` method. By escaping JavaScript string delimiters, attac...

CVE-2026-24737

HIGH CVSS 8.1 Feb 2, 2026

This vulnerability in jsPDF allows attackers to inject arbitrary PDF objects, including JavaScript actions, through user-controlled input to specific Acroform module methods and properties. When a vic...

CVE-2025-68428

HIGH CVSS 7.5 Jan 5, 2026

CVE-2025-68428 is a path traversal vulnerability in jsPDF's Node.js builds that allows attackers to read arbitrary local files when user-controlled input is passed to certain methods. This affects app...

CVE-2025-57810

HIGH CVSS 7.5 Aug 26, 2025

CVE-2025-57810 is a denial-of-service vulnerability in jsPDF library where user-controlled input to the addImage method can cause high CPU utilization. Attackers can provide malicious PNG files or URL...

CVE-2025-29907

HIGH CVSS 7.5 Mar 18, 2025

CVE-2025-29907 is a denial-of-service vulnerability in jsPDF library where attackers can pass malicious data URLs to addImage, html, or addSvgAsImage methods, causing high CPU utilization and service ...

CVE-2026-24133

MEDIUM CVSS 6.5 Feb 2, 2026

This vulnerability in jsPDF allows attackers to cause denial of service by providing malicious BMP files with large width/height values in their headers. When unsanitized image data or URLs are passed...

CVE-2026-24040

MEDIUM CVSS 4.8 Feb 2, 2026

CVE-2026-24040 is a concurrency vulnerability in jsPDF's addJS method that causes cross-user data leakage. When multiple users generate PDFs simultaneously in server-side environments, JavaScript cont...

CVE-2026-24043

MEDIUM CVSS 5.4 Feb 2, 2026

This vulnerability in jsPDF allows attackers to inject arbitrary XML metadata into generated PDFs by controlling the first argument of the addMetadata function. This compromises PDF integrity, particu...