logo

“PDF” Poison: Popular JavaScript Library Patches Critical Injection and Crash Flaws

ID: 534130da-3893-53b1-b3fe-f37ef1d2aa25

STIX ID: report--534130da-3893-53b1-b3fe-f37ef1d2aa25

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-02-06

Date Updated: 2026-04-23

Author: Ddos

...
...

Two high-severity vulnerabilities have been disclosed in the widely used jsPDF library: CVE-2026-24737 (CVSS 8.1) allows attackers to inject arbitrary PDF objects and JavaScript via the AcroForm APIs when user input is unsanitized, enabling data theft or unauthorized actions; CVE-2026-24133 (CVSS 8.7) is a bitmap-based denial-of-service in the BMPDecoder addImage method that can trigger excessive memory allocation and crash browsers or applications. Maintainers released fixes in jspdf@>=4.1.0 and advise developers to sanitize inputs and validate image data if upgrades cannot be applied immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.