VDB
Sign up
CRITICAL

GHSA-h3q6-jfrg-3x6q

survey-pdf Upgraded jsPDF Version Due to Security Vulnerability

Quick fix

GHSA-h3q6-jfrg-3x6q — survey-pdf: upgrade to the fixed version with the command below.

npm install survey-pdf@1.12.59

Details

The following security vulnerability was identified in jsPDF versions <=3.0.4: [Local File Inclusion/Path Traversal](https://github.com/parallax/jsPDF/security/advisories/GHSA-f8cm-6447-x5h2).

### Impact

Since SurveyJS PDF Generator depends on jsPDF, any project using `survey-pdf` v1.12.58 and lower or v2.5.4 and lower could be exposed to this vulnerability.

### Solution

SurveyJS PDF Generator has upgraded jsPDF to version >= 4.0.0 and included the fix in the following `survey-pdf` releases:

* [v1.12.59](https://www.npmjs.com/package/survey-pdf/v/1.12.59) * [v2.5.5](https://www.npmjs.com/package/survey-pdf/v/2.5.5)

### Action

Users should upgrade `survey-pdf` in their projects to v1.12.59+ or v2.5.5+ immediately.

### Notes

No other `survey-pdf` dependencies are affected. This update is fully backward-compatible with previous `survey-pdf` releases.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/survey-pdf
Introduced in: 0Fixed in: 1.12.59
Fixnpm install survey-pdf@1.12.59
npm/survey-pdf
Introduced in: 2.0.0Fixed in: 2.5.5
Fixnpm install survey-pdf@2.5.5

References