Junglewise Threat Intelligence

CVE-2026-82868: @pdfme/schemas before 5.5.9 contains a cross-site scripting vulnerability in the SVG schema plugin that renders user-supplied SVG content di

CVE-2026-82868 · Severity: medium · CVSS 6.1 · Published 2026-08-31

Technologies: @pdfme/schemas (npm). Vendors: npm, PDFME.

Executive brief

The pdfme PDF generation library contains a vulnerability in its SVG schema rendering component that allows attackers to inject malicious JavaScript code. When users view or fill PDF forms with SVG graphics, attackers can execute arbitrary code in their browsers to steal session tokens, capture keyboard input, or exfiltrate sensitive data. This risk is especially severe for SaaS platforms that allow users to upload or share custom PDF templates.

Technical details

The SVG schema plugin in @pdfme/schemas renders user-supplied SVG content directly to the DOM using container.innerHTML without sanitization. The isValidSVG() validation function only checks for basic XML structure but does not block malicious payloads such as script tags, event handler attributes (onload, onerror, onclick), foreignObject elements containing HTML with handlers, or animate/set elements with onbegin/onend attributes. An attacker can exploit this by crafting a malicious PDF template containing SVG content with embedded JavaScript, which executes when the template is loaded in a Form or Viewer component. User interaction is required (viewing or filling the form), and the attack vector is network-based. The vulnerability is fixed in version 5.5.9; earlier versions up to 5.5.8 are affected.

Affected products

  • pdfme @pdfme/schemas through 5.5.8

Timeline

  • 2026-03-18: disclosed
  • 2026-03-18: patched: Fixed in version 5.5.9

References

Related threats