Critical jsPDF flaw lets hackers steal secrets via generated PDFs
ID: ce6b5b0e-25ef-5c77-aa85-4dff6ac25bb3
STIX ID: report--ce6b5b0e-25ef-5c77-aa85-4dff6ac25bb3
Feed Name: Bleeping Computer
A critical path-traversal/local-file-inclusion vulnerability (CVE-2025-68428, CVSS 9.2) in jsPDF's Node.js builds allows attacker-supplied file paths to be read and embedded into generated PDFs—potentially exposing local sensitive files. The issue affects loadFile and callers (addImage, html, addFont), is fixed in jsPDF 4.0.0 by restricting filesystem access, but mitigations depend on Node permission modes and can be negated by overly permissive configurations; broad jsPDF adoption raises exploitation potential.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
