Code Injection in jspdf - CVE-2026-25755

 

Code Injection in jspdf - CVE-2026-25755

Published: April 27, 2026


Vulnerability identifier: #VU127969
CSH Severity: High
CVSS v4 BT: 6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Amber]
CVE-ID: CVE-2026-25755
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to inject arbitrary PDF objects into the generated document.

The vulnerability exists due to improper control of code generation in the addJS method when processing user-supplied JavaScript input. A remote attacker can supply a crafted addJS argument to inject arbitrary PDF objects into the generated document.

User interaction is required to open the generated PDF, and injected additional actions may execute when the document is opened or receives focus.


Affected software

jspdf
InfoSphere Optim Archive Viewer

How to mitigate CVE-2026-25755

Install security update from vendor's website.

jspdf - update to 4.2.0
InfoSphere Optim Archive Viewer - update to 11.7.0.14

External References

Related Security Bulletins