Improper Encoding or Escaping of Output in jspdf - CVE-2026-25940
Published: April 27, 2026
jspdf
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary JavaScript.
The vulnerability exists due to improper encoding or escaping of output in the AcroForm module when processing unsanitized input for the AcroformChildClass.appearanceState property. A remote attacker can supply a specially crafted property value to execute arbitrary JavaScript.
User interaction is required when the victim hovers over the radio option in the generated PDF.