CVE-2026-25755Disclosure(parall / jspdf)

MEDIUMCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch parall jspdf systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of the argument of the `addJS` method allows an attacker to inject arbitrary PDF objects into the generated document. By crafting a payload that escapes the JavaScript string delimiter, an attacker can execute malicious actions or alter the document structure, impacting any user who opens the generated PDF. The vulnerability has been fixed in [email protected]. As a workaround, escape parentheses in user-provided JavaScript code before passing them to the `addJS` method.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94CWE-116

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • jspdf

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 11 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 11 signals
  • Disclosure: 6 classified signals
  • Peaked 4d ago at 4 mentions (2026-02-23); latest day: 1
  • 11 total mentions across 6 days

Affected systems

Vendors
Products
jspdf

Deep dive

Activity timeline11 mentions / 6d
01234Mentions · 2026-02-19: 2Mentions · 2026-02-23: 4Mentions · 2026-02-24: 2Mentions · 2026-03-02: 1Mentions · 2026-03-05: 1Mentions · 2026-03-11: 1PoC Mentioned / Linked · 2026-02-19: 1PoC Mentioned / Linked · 2026-02-23: 1PoC Mentioned / Linked · 2026-02-24: 1Exploit Tool / Code · 2026-02-24: 1Patch / Workaround · 2026-02-23: 2Patch / Workaround · 2026-02-24: 1Technical Details · 2026-02-19: 2Technical Details · 2026-02-23: 4Technical Details · 2026-02-24: 2Technical Details · 2026-03-02: 1Technical Details · 2026-03-05: 1Technical Details · 2026-03-11: 102-1902-2302-2403-0203-0503-11
Signal classification4 categories
Disclosure
654.5%
Patch
327.3%
PoC
19.1%
General
19.1%
Referenced assets13 URLs
Classification over time
DateTotalLabels
2026-02-192
Disclosure2
2026-02-234
Disclosure2Patch2
2026-02-242
Patch1PoC1
2026-03-021
Disclosure1
2026-03-051
General1
2026-03-111
Disclosure1
Full discourse11 posts
  • Cyber Edition@CyberEdition
    Disclosure

    📄 jsPDF CVE-2026-25755: Object injection in addJS—arbitrary PDF structs even JS disabled. Web apps pwned! 👇 https://thecyberedition.com/jspdf-object-injection/ #ZeroDaysAndCVEs #jsPDF #Cybersecurity

    Post summary

    The post announces CVE-2026-25755 in jsPDF, detailing an object injection flaw that permits arbitrary PDF structures even when JavaScript is disabled, and links to a site likely containing further information.

    0002295
    668 followersView on X
  • absholi7ly@absholi7ly
    PoC

    #Poc (CVE-2026-25755) Sandbox Bypassed jsPDF Flaw to Object Injection https://github.com/absholi7ly/jsPDF-Object-Injection #jsPDF #PDF #Poc #vuln

    Post summary

    A proof‑of‑concept for CVE‑2026‑25755 is shared, demonstrating a sandbox bypass via object injection in jsPDF, with the PoC code hosted on GitHub.

    00021190
    219 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    jsPDF ライブラリの脆弱性 CVE-2026-25755 が FIX:オブジェクト・インジェクションの可能性 https://iototsecnews.jp/2026/02/23/jspdf-vulnerability-exposes-millions-of-developers-to-object-injection-attacks/ Web 開発において広く使われている PDF 生成ライブラリ「jsPDF」に、PDFの内部構造を不正に書き換えられる深刻な脆弱性 CVE-2026-25755 が発見されました。この問題の核心は、PDF 内に JavaScript を埋め込むための addJS メソッドにあります。ユーザーから入力されたテキストを、プログラムが PDF 形式に変換する際に、PDF のデータ構造を定義する “閉じ括弧” などの特殊文字を適切にエスケープせず、そのまま PDF のデータストリームに連結してしまう不備がありました。 今回の脆弱性は、一般的な JavaScript ベースの XSS とは性質が大きく異なり、PDF のオブジェクト階層を直接操作する、PDF Object Injection という手法を許すものです。これにより、たとえ PDF ビューア側で JavaScript の実行が制限されていても、文書を開いた瞬間に外部プログラム呼び出しなどのアクションが実行される可能性があります。ご利用のチームは、ご注意ください。 #CVE202625755 #jsPDF #Vulnerability

    Post summary

    The article presents the discovery of a severe jsPDF object‑injection vulnerability (CVE‑2026‑25755), describing its technical details but offering no proof‑of‑concept, exploit code, or patch information.

    02000201
    483 followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2026-25755** pertains to a security flaw in the popular JavaScript library **jsPDF**, which is used to generate PDF documents within web applications. Prior to version **4.2.0**, the `addJS` method in jsPDF allows user-controlled input to be injected directly into the PDF's JavaScript context. This vulnerability enables an attacker to craft malicious payloads that escape the JavaScript string delimiters, leading to arbitrary PDF object injection. #Cybersecurity #CVE #HighSeverity #SecurityAlert https://cvetodo.com/cve/CVE-2026-25755

    Post summary

    This post announces CVE-2026-25755, detailing that the pre‑4.2.0 addJS feature in jsPDF allows malicious JavaScript payloads to be injected into PDFs, explaining how the flaw operates and its high severity.

    1001028
    20 followersView on X
  • kantan.news@KantanNewsX
    Patch

    Popüler jsPDF kütüphanesinde keşfedilen kritik güvenlik açığı (CVE-2026-25755), milyonlarca geliştiriciyi PDF nesne enjeksiyonu saldırılarına açık hale getiriyor. Uygulamalarınızı korumak için jsPDF sürümünüzü acilen güncelleyin! Haberin detayı: https://kantan.news/x_article.php?slug=jspdf-ktphanesinde-kritik-gvenlik-a-milyonlarca-gelitirici-risk-altnda

    Post summary

    The post alerts developers to CVE‑2026‑25755, a PDF object injection flaw in jsPDF, and urges an immediate update to mitigate the risk.

    00010136
    793 followersView on X
  • SaltedHash Tech@Saltedhashtech
    Disclosure

    🚨Learn how CVE-2026-25755 affects the addJS method in jsPDF library that is used to embed JavaScript code in PDF files. https://www.saltedhashtech.com/blogs/millions-of-developers-exposed-jspdf-vulnerability-opens-door-to-object-injection #vapt #vulnerability #cve #vulnerabilityassessment #javascript #js #injection https://t.co/7xdeIScvlq

    Post summary

    The blog post announces CVE-2026-25755’s impact on jsPDF’s addJS method, providing technical detail but no PoC, exploit code, active exploitation, or patch information.

    0000038
    1 followersView on X
  • 0XJacks 𝕏@ZeroXJacks
    General

    الحمد لله الذيّ نظن به خيراً فيكرمنا بأفضل مِمّا ظننَّا به 😊❤️.CVE-2026-25755 https://isc.sans.edu/podcastdetail/9822 https://gbhackers.com/jspdf-millions-developers-exposed/ https://techlomedia.in/2026/02/jspdf-vulnerability-exposes-developers-to-serious-pdf-object-injection-risk-121146/ https://thehackernews.com/2026/03/weekly-recap-sd-wan-0-day-critical-cves.html?m=1 https://t.co/x6DIdwX5MA

    Post summary

    The post cites CVE‑2026‑25755 and links to several coverage pieces describing a jsPDF object‑injection flaw, but offers no PoC, exploit, patch, or evidence of active attacks.

    0000063
    8 followersView on X
  • The Daily Tech Feed@dailytechonx
    Patch

    Critical vulnerability CVE-2026-25755 found in jsPDF's `addJS` method allows PDF Object Injection attacks. Developers must update to version 4.1.0+ immediately. Link: https://thedailytechfeed.com/jspdf-security-flaw-cve-2026-25755-risks-pdf-object-injection-urgent-update-recommended/ #Security #Vulnerability #Update #Developers #JavaScript #PDF #Injection #Patch #Software #Exploit #Risk #Bug #Code #Fix #Technology #Alert #Protection #Threat #Hack #Patch

    Post summary

    The post announces a critical CVE-2026-25755 in jsPDF's addJS method that permits PDF Object Injection, urging developers to upgrade to version 4.1.0+ immediately.

    0000070
    240 followersView on X
  • 趣テクノロジー@omomuki_tech
    Disclosure

    人気のPDF生成ライブラリであるjsPDFに、深刻なセキュリティ上の欠陥が発見されました。この脆弱性(CVE-2026-25755)は、数百万人のWeb開発者をPDFオブジェクトインジェクション攻撃の危険にさらすものだと報告されています。 この脆弱性を悪用されると、リモートの攻撃者が、Webアプリケーションによって生成されるPDFドキュメント内に、任意のオブジェクトや不正なアクションを埋め込むことが可能になります。 記事によると、この問題はPDFファイルにJavaScriptコードを埋め込むための`addJS`メソッドに起因しています。ユーザーが入力した内容を適切にサニタイズ(無害化)する処理が不十分であったため、攻撃者がこれを悪用できる状態になっていました。jsPDFを利用して動的にPDFを生成している多くのWebアプリケーションが影響を受ける可能性がありますので、開発者の皆さんは注意が必要です。 #jsPDF #セキュリティ #脆弱性 https://cybersecuritynews.com/jspdf-vulnerability-injection-attacks/

    Post summary

    A newly disclosed CVE-2026-25755 in jsPDF allows remote attackers to inject arbitrary objects and JavaScript into PDFs via the addJS method, exposing many web applications to potential exploitation.

    0000043
    228 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 jsPDF addJS Injection Flaw (CVE-2026-25755): Remote PDF Object Injection Enables Malicious OpenAction Behavior A high-severity jsPDF bug (CVE-2026-25755) lets attackers inject arbitrary PDF objects/actions by breaking out of the `/JS ( ... )` string in `addJS()` due to missing escaping, enabling auto-triggered behaviors (e.g., `/OpenAction`) and document manipulation even when PDF JavaScript is disabled; upgrade to jsPDF 4.1.0+ and never feed untrusted input into `addJS`/related APIs. 🎯 Target: Global/Developers (Apps generating PDFs) #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cybersecuritynews.com/jspdf-vulnerability-injection-attacks/

    Post summary

    The article reports a high‑severity jsPDF addJS injection flaw (CVE‑2026‑25755) that allows arbitrary PDF object injection and auto‑triggered behaviors, and advises upgrading to jsPDF 4.1.0+ or avoiding untrusted input.

    0000054
    196 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-25755 - High jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of the argument of the `addJS` method allows an attacker to inject arbitrary PDF objects into the generated doc... https://www.thehackerwire.com/vulnerability/CVE-2026-25755/ https://t.co/5ToakZjL8a

    Post summary

    The post announces a newly disclosed vulnerability in jsPDF (CVE-2026-25755), highlighting the injection vector via the addJS method, with a link to further details but no mention of active exploitation or available patch.

    0000028
    112 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appparalljspdf-node.js-

Explore more