Executive brief
jsPDF is a popular JavaScript library used by web applications to generate PDF documents. A security flaw allows attackers to inject malicious code or hidden commands into generated PDFs if the application uses untrusted user input. When a victim opens such a PDF, the injected content could lead to unauthorized actions, data theft, or the display of deceptive information, even if the user has disabled JavaScript in their PDF viewer.
Technical details
A PDF Object Injection vulnerability exists in the `addJS` method of jsPDF due to improper sanitization of the closing parenthesis `)` character. In the PDF specification, the parenthesis acts as a delimiter for literal strings; by providing a crafted payload, an attacker can escape the intended JavaScript string context and inject raw PDF dictionaries and actions (e.g., `/AA` or `/OpenAction`). This bypasses typical PDF JavaScript sandboxes and can execute even in viewers where JavaScript is disabled. The vulnerability is fixed in version 4.2.0 by properly escaping parentheses and backslashes.
Affected products
- parallax jsPDF < 4.2.0
- Red Hat Red Hat Advanced Cluster Security for Kubernetes 4.8, 4.9
Timeline
- 2026-02-19: disclosed
- 2026-02-19: patched: Fixed in jsPDF v4.2.0
- 2026-02-19: advisory
- 2026-04-08: patched: Red Hat released RHSA-2026:7110 for RHACS
References
- https://github.com/ZeroXJacks/CVEs/blob/main/2026/CVE-2026-25755.md
- https://github.com/parallax/jsPDF/commit/56b46d45b052346f5995b005a34af5dcdddd5437
- https://github.com/parallax/jsPDF/releases/tag/v4.2.0
- https://github.com/parallax/jsPDF/security/advisories/GHSA-9vjf-qc39-jprp
- https://access.redhat.com/errata/RHSA-2026:7110
- https://access.redhat.com/errata/RHSA-2026:7128
- https://access.redhat.com/security/cve/CVE-2026-25755