CVE-2025-68428Patch(parall / jspdf)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch parall jspdf systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.0.0, user control of the first argument of the loadFile method in the node.js build allows local file inclusion/path traversal. If given the possibility to pass unsanitized paths to the loadFile method, a user can retrieve file contents of arbitrary files in the local file system the node process is running in. The file contents are included verbatim in the generated PDFs. Other affected methods are `addImage`, `html`, and `addFont`. Only the node.js builds of the library are affected, namely the `dist/jspdf.node.js` and `dist/jspdf.node.min.js` files. The vulnerability has been fixed in [email protected]. This version restricts file system access per default. This semver-major update does not introduce other breaking changes. Some workarounds areavailable. With recent node versions, jsPDF recommends using the `--permission` flag in production. The feature was introduced experimentally in v20.0.0 and is stable since v22.13.0/v23.5.0/v24.0.0. For older node versions, sanitize user-provided paths before passing them to jsPDF.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-35CWE-73CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • jspdf

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-02-04); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
jspdf

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-04: 1Mentions · 2026-02-07: 1Patch / Workaround · 2026-02-04: 1Technical Details · 2026-02-04: 1Technical Details · 2026-02-07: 102-0402-07
Signal classification2 categories
Patch
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-041
Patch1
2026-02-071
Disclosure1
Full discourse2 posts
  • Komodo Cyber Security@Komodosec
    Disclosure

    #VulnerabilityReport #CVE202568428 CVE-2025-68428: Critical Flaw in jsPDF Library Allows Server-Side File Theft https://securityonline.info/cve-2025-68428-critical-flaw-in-jspdf-library-allows-server-side-file-theft/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    The tweet announces a new critical CVE‑2025‑68428 in the jsPDF library that enables server‑side file theft, but provides no PoC, exploit code, active exploitation evidence, or patch information.

    0001070
    1.5K followersView on X
  • Nancy Chauhan@_nancychauhan
    Patch

    🔴 CVE-2025-68428 -- a path traversal flaw in jsPDF (CVSS 9.2/10) that lets attackers read arbitrary server files through generated PDFs. I submitted a fix and it was merged: https://github.com/apache/superset/pull/37553 🥳

    Post summary

    The post announces a high‑severity path traversal vulnerability in jsPDF and confirms that a patch has been merged, providing a link to the fix.

    10000107
    3.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appparalljspdf-node.js-

Explore more