logo

Critical jsPDF flaw lets hackers steal secrets via generated PDFs

ID: ce6b5b0e-25ef-5c77-aa85-4dff6ac25bb3

STIX ID: report--ce6b5b0e-25ef-5c77-aa85-4dff6ac25bb3

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2026-01-07

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A critical path-traversal/local-file-inclusion vulnerability (CVE-2025-68428, CVSS 9.2) in jsPDF's Node.js builds allows attacker-supplied file paths to be read and embedded into generated PDFs—potentially exposing local sensitive files. The issue affects loadFile and callers (addImage, html, addFont), is fixed in jsPDF 4.0.0 by restricting filesystem access, but mitigations depend on Node permission modes and can be negated by overly permissive configurations; broad jsPDF adoption raises exploitation potential.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.