MEDIUM6.1
GHSA-g9wg-98c2-qv3v
TCPDF Cross-site Scripting vulnerability
Quick fix
GHSA-g9wg-98c2-qv3v — tecnickcom/tcpdf: upgrade to the fixed version with the command below.
composer require tecnickcom/tcpdf:^6.7.4Details
TCPDF before 6.7.4 mishandles calls that use HTML syntax.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/tecnickcom/tcpdf
Introduced in:
0Fixed in: 6.7.4Fix
composer require tecnickcom/tcpdf:^6.7.4References
- https://nvd.nist.gov/vuln/detail/CVE-2024-32489[ADVISORY]
- https://github.com/tecnickcom/TCPDF/commit/51cd1b39de5643836e62661d162c472d63167df7[WEB]
- https://github.com/tecnickcom/TCPDF/commit/82fc97bf1c74c8dbe62b1d3cc6d10fa4b87e0262[WEB]
- https://github.com/tecnickcom/TCPDF[PACKAGE]
- https://github.com/tecnickcom/TCPDF/compare/6.6.2...6.7.4[WEB]
- https://lists.debian.org/debian-lts-announce/2025/06/msg00004.html[WEB]