CVE-2026-24737Disclosure(parall / jspdf)

LOWCVSS 8.1 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch parall jspdf systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, user control of properties and methods of the Acroform module allows users to inject arbitrary PDF objects, such as JavaScript actions. If given the possibility to pass unsanitized input to one of the following methods or properties, a user can inject arbitrary PDF objects, such as JavaScript actions, which are executed when the victim opens the document. The vulnerable API members are AcroformChoiceField.addOption, AcroformChoiceField.setOptions, AcroFormCheckBox.appearanceState, and AcroFormRadioButton.appearanceState. The vulnerability has been fixed in [email protected].

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-116CWE-917

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • jspdf

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-02-09)
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
jspdf

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-02-02: 1Mentions · 2026-02-03: 1Mentions · 2026-02-09: 2Patch / Workaround · 2026-02-09: 2Technical Details · 2026-02-02: 1Technical Details · 2026-02-03: 1Technical Details · 2026-02-09: 202-0202-0302-09
Signal classification2 categories
Disclosure
250.0%
Patch
250.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-021
Disclosure1
2026-02-031
Disclosure1
2026-02-092
Patch2
Full discourse4 posts
  • セキュリティ対策Lab@securityLab_jp
    Patch

    jsPDFにPDF注入とDoSの高リスクの脆弱性、緊急アップデート呼びかけ(CVE-2026-24737,CVE-2026-24133) https://rocket-boys.co.jp/security-measures-lab/high-risk-jspdf-vulnerabilities-enable-pdf-injection-and-dos-urgent-update-urged-cve-2026-24737-cve-2026-24133/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    High‑risk vulnerabilities in jsPDF (PDF injection and DoS) have been disclosed, prompting an urgent update call for affected users.

    01020161
    318 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-24737 jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, user control of properties and methods of the Acroform module allows users to inject arbitrary PDF … https://www.cve.org/CVERecord?id=CVE-2026-24737

    Post summary

    CVE-2026-24737 is a vulnerability in jsPDF that permits arbitrary PDF injection via the Acroform module prior to version 4.1.0.

    02010289
    56.5K followersView on X
  • サイバーセキュリティニュース-JP@cybersecnews_jp
    Patch

    jsPDFにPDF注入とDoSの高リスクの脆弱性、緊急アップデート呼びかけ(CVE-2026-24737,CVE-2026-24133) https://rocket-boys.co.jp/security-measures-lab/high-risk-jspdf-vulnerabilities-enable-pdf-injection-and-dos-urgent-update-urged-cve-2026-24737-cve-2026-24133/

    Post summary

    The Japanese advisory warns about high‑risk PDF injection and DoS vulnerabilities (CVE‑2026‑24737, CVE‑2026‑24133) in jsPDF and urges users to apply an urgent update.

    0000063
    44 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-24737 PDF Object Injection Vulnerability in jsPDF Library Before 4.1.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-24737

    Post summary

    The text announces CVE-2026-24737 as a PDF object injection vulnerability in jsPDF versions prior to 4.1.0, providing basic disclosure details without any PoC, exploit, patch, or active exploitation information.

    0000092
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appparalljspdf-node.js-

Explore more