VDB
Sign up
HIGH8.1

GHSA-9vjf-qc39-jprp

jsPDF has a PDF Object Injection via Unsanitized Input in addJS Method

Quick fix

GHSA-9vjf-qc39-jprp — jspdf: upgrade to the fixed version with the command below.

npm install jspdf@4.2.0

Details

### Impact

User control of the argument of the `addJS` method allows an attacker to inject arbitrary PDF objects into the generated document. By crafting a payload that escapes the JavaScript string delimiter, an attacker can execute malicious actions or alter the document structure, impacting any user who opens the generated PDF.

```js import { jsPDF } from "jspdf"; const doc = new jsPDF(); // Payload: // 1. ) closes the JS string. // 2. > closes the current dictionary. // 3. /AA ... injects an "Additional Action" that executes on focus/open. const maliciousPayload = "console.log('test');) >> /AA << /O << /S /JavaScript /JS (app.alert('Hacked!')) >> >>";

doc.addJS(maliciousPayload); doc.save("vulnerable.pdf"); ```

### Patches The vulnerability has been fixed in jspdf@4.2.0.

### Workarounds Escape parentheses in user-provided JavaScript code before passing them to the `addJS` method. ### References https://github.com/ZeroXJacks/CVEs/blob/main/2026/CVE-2026-25755.md

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/jspdf
Introduced in: 0Fixed in: 4.2.0
Fixnpm install jspdf@4.2.0

References