Executive brief
jsPDF is a popular JavaScript library used by developers to generate PDF documents within web applications. A vulnerability in its form-handling module allows attackers to create malicious PDF files that execute unauthorized code when opened by a user. This could lead to the theft of sensitive information or unauthorized actions being performed on the victim's behalf.
Technical details
A PDF injection vulnerability exists in the Acroform module of jsPDF due to improper encoding or escaping of output (CWE-116). Specifically, the API members AcroformChoiceField.addOption, AcroformChoiceField.setOptions, AcroFormCheckBox.appearanceState, and AcroFormRadioButton.appearanceState fail to sanitize input, allowing an attacker to inject arbitrary PDF objects. By crafting a payload that closes existing arrays and injects Additional Action (/AA) or JavaScript (/JS) keys, an attacker can execute arbitrary JavaScript when a victim opens the generated document. This requires the application to pass unsanitized user input into the affected jsPDF methods. The issue is resolved in version 4.1.0.
Affected products
- parallax jsPDF < 4.1.0
- Red Hat Red Hat Advanced Cluster Security for Kubernetes 4.8 4.8.9
- Red Hat Red Hat Advanced Cluster Security for Kubernetes 4.9 4.9.0
Timeline
- 2026-02-02: disclosed
- 2026-02-02: patched: Fixed in jsPDF version 4.1.0
- 2026-02-02: advisory
- 2026-03-12: advisory: Red Hat advisory RHSA-2026:4466 issued
References
- https://github.com/parallax/jsPDF/commit/da291a5f01b96282545c9391996702cdb8879f79
- https://github.com/parallax/jsPDF/releases/tag/v4.1.0
- https://github.com/parallax/jsPDF/security/advisories/GHSA-pqxr-3g65-p328
- https://access.redhat.com/errata/RHSA-2026:4466
- https://access.redhat.com/errata/RHSA-2026:4467
- https://access.redhat.com/security/cve/CVE-2026-24737
- https://bugzilla.redhat.com/show_bug.cgi?id=2436115