Junglewise Threat Intelligence

CVE-2026-24043: jsPDF XML injection in addMetadata function

CVE-2026-24043 · Severity: medium · CVSS 4 · Published 2026-02-02

Technologies: jspdf (npm). Vendors: Parallax, npm.

Executive brief

jsPDF is a JavaScript library used to generate PDF documents in web applications. An attacker who can supply unsanitized input to the addMetadata() function can inject malicious XML metadata into generated PDFs, allowing them to forge the document's author field or other metadata to impersonate trusted sources. This undermines the integrity and authenticity of electronically signed or archived PDFs.

Technical details

This is a stored XMP metadata injection vulnerability (CWE-20, CWE-74) in jsPDF's addMetadata() function. The vulnerability occurs because user-supplied input passed to addMetadata() is not sanitized before being embedded into the PDF's XMP metadata stream. An attacker can inject XML tags to break out of the current metadata structure and inject arbitrary XML, such as forged author or creator fields. The attack requires network access and the ability to pass unsanitized user input to the addMetadata() method, but requires no authentication or user interaction. Successful exploitation allows integrity violation of signed PDFs and document spoofing. The vulnerability was fixed in jsPDF version 4.1.0; all versions 4.0.0 and earlier are affected.

Affected products

  • parallax jsPDF <=4.0.0

Timeline

  • 2026-02-02: disclosed
  • 2026-02-02: patched: Fixed in jsPDF 4.1.0

References

Related threats