Improper Encoding or Escaping of Output in jspdf - CVE-2026-31898

 

Improper Encoding or Escaping of Output in jspdf - CVE-2026-31898

Published: April 27, 2026


Vulnerability identifier: #VU127971
CSH Severity: High
CVSS v4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-31898
CWE-ID: CWE-116
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to inject arbitrary PDF objects.

The vulnerability exists due to improper encoding or escaping of output in the createAnnotation method when processing the color parameter of a free text annotation. A remote attacker can supply crafted input to inject arbitrary PDF objects.

User interaction is required to open or interact with the generated PDF for injected actions to trigger.


Affected software

jspdf

How to mitigate CVE-2026-31898

Install security update from vendor's website.

jspdf - update to 4.2.1

External References

Related Security Bulletins