Junglewise Threat Intelligence

CVE-2026-24737: parallax jsPDF PDF injection in Acroform module

CVE-2026-24737 · Severity: high · CVSS 8.1 · Published 2026-02-02

Technologies: Red Hat Advanced Cluster Security for Kubernetes, jspdf (npm). Vendors: Red Hat, Parallax, npm.

Executive brief

jsPDF is a popular JavaScript library used by developers to generate PDF documents within web applications. A vulnerability in its form-handling module allows attackers to create malicious PDF files that execute unauthorized code when opened by a user. This could lead to the theft of sensitive information or unauthorized actions being performed on the victim's behalf.

Technical details

A PDF injection vulnerability exists in the Acroform module of jsPDF due to improper encoding or escaping of output (CWE-116). Specifically, the API members AcroformChoiceField.addOption, AcroformChoiceField.setOptions, AcroFormCheckBox.appearanceState, and AcroFormRadioButton.appearanceState fail to sanitize input, allowing an attacker to inject arbitrary PDF objects. By crafting a payload that closes existing arrays and injects Additional Action (/AA) or JavaScript (/JS) keys, an attacker can execute arbitrary JavaScript when a victim opens the generated document. This requires the application to pass unsanitized user input into the affected jsPDF methods. The issue is resolved in version 4.1.0.

Affected products

  • parallax jsPDF < 4.1.0
  • Red Hat Red Hat Advanced Cluster Security for Kubernetes 4.8 4.8.9
  • Red Hat Red Hat Advanced Cluster Security for Kubernetes 4.9 4.9.0

Timeline

  • 2026-02-02: disclosed
  • 2026-02-02: patched: Fixed in jsPDF version 4.1.0
  • 2026-02-02: advisory
  • 2026-03-12: advisory: Red Hat advisory RHSA-2026:4466 issued

References

Related threats