CVE-2026-25940Disclosure(parall / jspdf)

MEDIUMCVSS 8.1 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch parall jspdf systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of properties and methods of the Acroform module allows users to inject arbitrary PDF objects, such as JavaScript actions. If given the possibility to pass unsanitized input to one of the following property, a user can inject arbitrary PDF objects, such as JavaScript actions, which are executed when the victim hovers over the radio option. The vulnerability has been fixed in [email protected]. As a workaround, sanitize user input before passing it to the vulnerable API members.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-116

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • jspdf

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 4 mentions (2026-02-19); latest day: 1
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
jspdf

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-02-19: 4Mentions · 2026-03-02: 1PoC Mentioned / Linked · 2026-03-02: 1Exploit Tool / Code · 2026-03-02: 1Patch / Workaround · 2026-02-19: 1Technical Details · 2026-02-19: 402-1903-02
Signal classification4 categories
Disclosure
240.0%
General
120.0%
Patch
120.0%
PoC
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-194
Disclosure2General1Patch1
2026-03-021
PoC1
Full discourse5 posts
  • blueblue@piedpiper1616
    PoC

    GitHub - dajneem23/CVE-2026-25940 - https://github.com/dajneem23/CVE-2026-25940

    Post summary

    A GitHub repository has been published for CVE-2026-25940, likely containing a proof‑of‑concept or exploit code, but no details on active exploitation, patches, or technical specifics are provided.

    01011839
    5.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25940 Arbitrary PDF Object Injection via Unsanitized Input in jsPDF Before 4.2.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25940

    Post summary

    CVE-2026-25940 is a PDF injection vulnerability in jsPDF versions prior to 4.2.0 caused by unsanitized input. The report provides technical details but no PoC, exploit code, or evidence of active exploitation.

    0001147
    4.0K followersView on X
  • The Hacker Wire@TheHackerWire
    General

    🟠 CVE-2026-25940 - High jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of properties and methods of the Acroform module allows users to inject arbitrary PDF objects, such as JavaScri... https://www.thehackerwire.com/vulnerability/CVE-2026-25940/ https://t.co/8t3tcvbsGr

    Post summary

    The tweet reports CVE‑2026‑25940 in jsPDF, detailing that user-controlled Acroform can inject arbitrary PDF objects, but offers no PoC, patch, or evidence of active exploitation.

    1001039
    112 followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2026-25940** pertains to the **jsPDF** library, a popular JavaScript library used to generate PDF documents within web applications. Prior to version **4.2.0**, the library's **Acroform module** exposed a vulnerability where user-controlled input could be used to inject arbitrary PDF objects, including JavaScript actions, into generated PDFs. #Cybersecurity #CVE #HighSeverity #SecurityAlert #RemoteCodeExecution #Adobe https://cvetodo.com/cve/CVE-2026-25940

    Post summary

    The post announces CVE-2026‑25940 against jsPDF’s Acroform module, revealing that pre‑4.2.0 versions allow user‑controlled input to inject malicious PDF objects and JavaScript actions into generated PDFs.

    0000040
    20 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 HIGH severity alert: jsPDF < 4.2.0 allows PDF-based code injection via improper output encoding in Acroform. User interaction triggers malicious actions. Patch now! 🔒 https://radar.offseq.com/threat/cve-2026-25940-cwe-116-improper-encoding-or-escapi-3b5e393d #OffSeq #jsPDF #... https://t.co/Ko6d3rR7ht

    Post summary

    The tweet alerts a high‑severity PDF code‑injection flaw in jsPDF versions before 4.2.0 (CVE‑2026‑25940) and urges immediate patching.

    0000030
    265 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appparalljspdf-node.js-

Explore more