Executive brief
The @pdfme/schemas library is used to render PDF templates with form fields in web browsers. An attacker who can upload or supply a malicious PDF template can inject JavaScript code through crafted option values in select form fields. When a user views the template, the malicious script executes in their browser, enabling account hijacking, data theft, or phishing attacks.
Technical details
This is a Cross-Site Scripting (CWE-79) vulnerability in the Select schema renderer. The vulnerable code in packages/schemas/src/select/index.ts (lines 159-164) builds HTML for <option> elements by directly interpolating unsanitized option values from the template JSON into an HTML string, then assigns it to innerHTML. An attacker can break out of the value attribute using a payload like `"></option><img src=x onerror="alert(document.domain)">` in the schema.options array. The attack vector is network-based with no privilege requirement but requires user interaction (viewing/rendering the template). Attack preconditions include the ability to supply or upload a malicious template, which can occur via file upload, shared templates in multi-tenant apps, or databases without sanitization. The fix is to use DOM APIs (createElement, appendChild) instead of innerHTML, or to HTML-encode option values before interpolation. Versions <= 5.5.8 are affected; version 5.5.9+ contains the patch.
Affected products
- pdfme @pdfme/schemas <= 5.5.8
Timeline
- 2026-03-18: disclosed
- 2026-03-18: patched: Fixed in version 5.5.9 and later