Critical jsPDF Vulnerability Enables Arbitrary File Read in Node.js (CVE-2025-68428)
ID: 854ea6df-066a-511f-ae4d-42f80ea126d5
STIX ID: report--854ea6df-066a-511f-ae4d-42f80ea126d5
Feed Name: Security Boulevard
Threat Score
In January 2026 a critical path traversal vulnerability (CVE-2025-68428, CVSS 9.2) was disclosed in jsPDF's Node.js builds that can be abused to read arbitrary files from servers generating PDFs; organizations using server-side jsPDF should upgrade to jsPDF 4.0.0, ensure compatible Node.js permission mode, and implement strict path validation/allowlisting to prevent sensitive data disclosure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
