Improper Encoding or Escaping of Output in jspdf - CVE-2026-25940

 

Improper Encoding or Escaping of Output in jspdf - CVE-2026-25940

Published: April 27, 2026


Vulnerability identifier: #VU127967
CSH Severity: High
CVSS v4 BT: 6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Amber]
CVE-ID: CVE-2026-25940
CWE-ID: CWE-116
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary JavaScript.

The vulnerability exists due to improper encoding or escaping of output in the AcroForm module when processing unsanitized input for the AcroformChildClass.appearanceState property. A remote attacker can supply a specially crafted property value to execute arbitrary JavaScript.

User interaction is required when the victim hovers over the radio option in the generated PDF.


Affected software

jspdf
InfoSphere Optim Archive Viewer

How to mitigate CVE-2026-25940

Install security update from vendor's website.

jspdf - update to 4.2.0
InfoSphere Optim Archive Viewer - update to 11.7.0.14

External References

Related Security Bulletins