jsPDF是Parallax开源的一款基于JavaScript的PDF文档生成库。 jsPDF 4.2.0之前版本存在安全漏洞,该漏洞源于addJS方法对用户输入处理不当,可能导致注入任意PDF对象。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | CVE-2026-25755 A critical PDF Object Injection vulnerability in jsPDF allows attackers to inject arbitrary PDF objects through the addJS() function, enabling AcroJS sandbox bypass and automatic script execution when PDFs are opened. | https://github.com/absholi7ly/jsPDF-Object-Injection | POC Details |
No public POC found.
Login to generate AI POC| CVE-2026-25535 | 8.7 HIGH | jsPDF Affected by Client-Side/Server-Side Denial of Service via Malicious GIF Dimensions |
| CVE-2026-25940 | 8.1 HIGH | jsPDF's PDF Injection in AcroForm module allows Arbitrary JavaScript Execution (RadioButto |
No comments yet