“PDF” Poison: Popular JavaScript Library Patches Critical Injection and Crash Flaws
ID: 534130da-3893-53b1-b3fe-f37ef1d2aa25
STIX ID: report--534130da-3893-53b1-b3fe-f37ef1d2aa25
Feed Name: securityonline.info
Two high-severity vulnerabilities have been disclosed in the widely used jsPDF library: CVE-2026-24737 (CVSS 8.1) allows attackers to inject arbitrary PDF objects and JavaScript via the AcroForm APIs when user input is unsanitized, enabling data theft or unauthorized actions; CVE-2026-24133 (CVSS 8.7) is a bitmap-based denial-of-service in the BMPDecoder addImage method that can trigger excessive memory allocation and crash browsers or applications. Maintainers released fixes in jspdf@>=4.1.0 and advise developers to sanitize inputs and validate image data if upgrades cannot be applied immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
