Improper Encoding or Escaping of Output in jspdf - CVE-2026-25940
Published: April 27, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary JavaScript.
The vulnerability exists due to improper encoding or escaping of output in the AcroForm module when processing unsanitized input for the AcroformChildClass.appearanceState property. A remote attacker can supply a specially crafted property value to execute arbitrary JavaScript.
User interaction is required when the victim hovers over the radio option in the generated PDF.
Affected software
InfoSphere Optim Archive Viewer
How to mitigate CVE-2026-25940
InfoSphere Optim Archive Viewer - update to 11.7.0.14