Junglewise Threat Intelligence

CVE-2026-82867: @pdfme/schemas before 5.5.9 contains a cross-site scripting vulnerability in the Select schema plugin that fails to sanitize option values b

CVE-2026-82867 · Severity: medium · CVSS 6.1 · Published 2026-08-31

Technologies: @pdfme/schemas (npm). Vendors: PDFME, npm.

Executive brief

The @pdfme/schemas library is used to render PDF templates with form fields in web browsers. An attacker who can upload or supply a malicious PDF template can inject JavaScript code through crafted option values in select form fields. When a user views the template, the malicious script executes in their browser, enabling account hijacking, data theft, or phishing attacks.

Technical details

This is a Cross-Site Scripting (CWE-79) vulnerability in the Select schema renderer. The vulnerable code in packages/schemas/src/select/index.ts (lines 159-164) builds HTML for <option> elements by directly interpolating unsanitized option values from the template JSON into an HTML string, then assigns it to innerHTML. An attacker can break out of the value attribute using a payload like `"></option><img src=x onerror="alert(document.domain)">` in the schema.options array. The attack vector is network-based with no privilege requirement but requires user interaction (viewing/rendering the template). Attack preconditions include the ability to supply or upload a malicious template, which can occur via file upload, shared templates in multi-tenant apps, or databases without sanitization. The fix is to use DOM APIs (createElement, appendChild) instead of innerHTML, or to HTML-encode option values before interpolation. Versions <= 5.5.8 are affected; version 5.5.9+ contains the patch.

Affected products

  • pdfme @pdfme/schemas <= 5.5.8

Timeline

  • 2026-03-18: disclosed
  • 2026-03-18: patched: Fixed in version 5.5.9 and later

References

Related threats