logo

Critical jsPDF Vulnerability Enables Arbitrary File Read in Node.js (CVE-2025-68428)

ID: 854ea6df-066a-511f-ae4d-42f80ea126d5

STIX ID: report--854ea6df-066a-511f-ae4d-42f80ea126d5

Feed Name: Security Boulevard

Threat Score
70/100

Date Published: 2026-01-12

Date Updated: 2026-04-22

Author: Theklis Stefani

...
...

In January 2026 a critical path traversal vulnerability (CVE-2025-68428, CVSS 9.2) was disclosed in jsPDF's Node.js builds that can be abused to read arbitrary files from servers generating PDFs; organizations using server-side jsPDF should upgrade to jsPDF 4.0.0, ensure compatible Node.js permission mode, and implement strict path validation/allowlisting to prevent sensitive data disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.