logo

Invisible Ink: Critical 9.6 CVSS jsPDF Flaw Turns Generated Documents into XSS Traps

ID: 1048c2ff-74e1-575d-ac18-8060155f4b6f

STIX ID: report--1048c2ff-74e1-575d-ac18-8060155f4b6f

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-03-19

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical vulnerability (CVE-2026-31938, CVSS 9.6) in jsPDF up to v4.2.0 allows attackers to inject and execute scripts via the output() method's options (e.g., filename and URL parameters), enabling cross-site scripting in victims' browsers; the issue is patched in jsPDF 4.2.1 and users are advised to upgrade or sanitize inputs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.