← לוח פגיעויות

CVE-2026-31898

בינונית 6.5

תיאור (מקור, אנגלית)

jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of arguments of the `createAnnotation` method allows users to inject arbitrary PDF objects, such as JavaScript actions. If given the possibility to pass unsanitized input to the following method, a user can inject arbitrary PDF objects, such as JavaScript actions, which might trigger when the PDF is opened or interacted with the `createAnnotation`: `color` parameter. The vulnerability has been fixed in [email protected]. As a workaround, sanitize user input before passing it to the vulnerable API members.

מדדים

CVSS 3.1
6.5 (MEDIUM) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
EPSS — סבירות ניצול
0% (אחוזון 000) נכון ל-26/7/2026
CWE
CWE-116, CWE-94

מוצרים מושפעים

parall: jspdf

קישורים