Количество 5
Количество 5
CVE-2026-31898
jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of arguments of the `createAnnotation` method allows users to inject arbitrary PDF objects, such as JavaScript actions. If given the possibility to pass unsanitized input to the following method, a user can inject arbitrary PDF objects, such as JavaScript actions, which might trigger when the PDF is opened or interacted with the `createAnnotation`: `color` parameter. The vulnerability has been fixed in jsPDF@4.2.1. As a workaround, sanitize user input before passing it to the vulnerable API members.
CVE-2026-31898
jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of arguments of the `createAnnotation` method allows users to inject arbitrary PDF objects, such as JavaScript actions. If given the possibility to pass unsanitized input to the following method, a user can inject arbitrary PDF objects, such as JavaScript actions, which might trigger when the PDF is opened or interacted with the `createAnnotation`: `color` parameter. The vulnerability has been fixed in jsPDF@4.2.1. As a workaround, sanitize user input before passing it to the vulnerable API members.
CVE-2026-31898
jsPDF is a library to generate PDFs in JavaScript. Prior to version 4. ...
GHSA-7x6v-j9x4-qf24
jsPDF has a PDF Object Injection via FreeText color
BDU:2026-05059
Уязвимость метода createAnnotation библиотеки для создания PDF-файлов jsPDF, позволяющая нарушителю выполнить произвольный код
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-31898 jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of arguments of the `createAnnotation` method allows users to inject arbitrary PDF objects, such as JavaScript actions. If given the possibility to pass unsanitized input to the following method, a user can inject arbitrary PDF objects, such as JavaScript actions, which might trigger when the PDF is opened or interacted with the `createAnnotation`: `color` parameter. The vulnerability has been fixed in jsPDF@4.2.1. As a workaround, sanitize user input before passing it to the vulnerable API members. | CVSS3: 8.1 | 0% Низкий | 5 месяцев назад | |
CVE-2026-31898 jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of arguments of the `createAnnotation` method allows users to inject arbitrary PDF objects, such as JavaScript actions. If given the possibility to pass unsanitized input to the following method, a user can inject arbitrary PDF objects, such as JavaScript actions, which might trigger when the PDF is opened or interacted with the `createAnnotation`: `color` parameter. The vulnerability has been fixed in jsPDF@4.2.1. As a workaround, sanitize user input before passing it to the vulnerable API members. | CVSS3: 8.1 | 0% Низкий | 5 месяцев назад | |
CVE-2026-31898 jsPDF is a library to generate PDFs in JavaScript. Prior to version 4. ... | CVSS3: 8.1 | 0% Низкий | 5 месяцев назад | |
GHSA-7x6v-j9x4-qf24 jsPDF has a PDF Object Injection via FreeText color | CVSS3: 8.1 | 0% Низкий | 5 месяцев назад | |
BDU:2026-05059 Уязвимость метода createAnnotation библиотеки для создания PDF-файлов jsPDF, позволяющая нарушителю выполнить произвольный код | CVSS3: 8.1 | 0% Низкий | 5 месяцев назад |
Уязвимостей на страницу