CVE-2026-31898Disclosure(parall / jspdf)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch parall jspdf systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of arguments of the `createAnnotation` method allows users to inject arbitrary PDF objects, such as JavaScript actions. If given the possibility to pass unsanitized input to the following method, a user can inject arbitrary PDF objects, such as JavaScript actions, which might trigger when the PDF is opened or interacted with the `createAnnotation`: `color` parameter. The vulnerability has been fixed in [email protected]. As a workaround, sanitize user input before passing it to the vulnerable API members.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-116CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • jspdf

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 6 classified signals
  • Peaked 1d ago at 6 mentions (2026-03-18); latest day: 1
  • 7 total mentions across 2 days

Affected systems

Vendors
Products
jspdf

Deep dive

Activity timeline7 mentions / 2d
02356Mentions · 2026-03-18: 6Mentions · 2026-03-25: 1Patch / Workaround · 2026-03-18: 2Technical Details · 2026-03-18: 5Technical Details · 2026-03-25: 103-1803-25
Signal classification2 categories
Disclosure
685.7%
Patch
114.3%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-186
Disclosure5Patch1
2026-03-251
Disclosure1
Full discourse7 posts
  • IntegSec@integ_sec
    Disclosure

    CVE-2026-31898 affects jsPDF and can let attackers inject malicious PDF content; learn business impact, exposure signs, and response steps. https://hubs.li/Q048h1gq0

    Post summary

    The text announces CVE-2026-31898 affecting jsPDF with a content injection flaw, provides guidance on business impact and response steps, but does not mention PoCs, exploits, or patches.

    0000023
    29 followersView on X
  • Fernando Karl@fernandokarl
    Patch

    🚨 Atenção, desenvolvedores! A vulnerabilidade no jsPDF (antes da v4.2.1) permite injeção de objetos PDF maliciosos através de `createAnnotation`. Mantenha seus PDFs seguros: atualize e valide entradas! 🔒 Saiba mais: https://www.tenable.com/cve/CVE-2026-31898 #CyberSecurity #jsPDF #Vulnerability

    Post summary

    The tweet warns about a PDF object injection flaw in jsPDF before v4.2.1, recommends updating and validating inputs, and links to Tenable for more details.

    0000044
    258 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-31898 PDF Object Injection in jsPDF Library Prior to Version 4.2.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-31898

    Post summary

    The text announces CVE‑2026‑31898, a PDF Object Injection vulnerability in jsPDF prior to v4.2.1, but provides no PoC, exploits, or mitigation details.

    0000041
    4.0K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-31898 - High jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of arguments of the `createAnnotation` method allows users to inject arbitrary PDF objects, such as Jav... https://www.thehackerwire.com/vulnerability/CVE-2026-31898/ https://t.co/ERSbReuLM6

    Post summary

    The tweet announces a high‑severity vulnerability in jsPDF, highlighting that versions before 4.2.1 allow arbitrary PDF object injection via the createAnnotation method, and implies a patch exists in newer releases.

    00000217
    138 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-31898 📊 Severity: 8.1 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-31898 #CVE-2026-31898 #CVE #High  #CyberSecurity #InfoSec https://t.co/aQxony3bLq

    Post summary

    The tweet announces the new CVE-2026-31898 with a severity of 8.1, but provides no technical details, exploitation information, or patch guidance.

    0000034
    104 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-31898 - jsPDF has a PDF Object Injection via FreeText color Intel Report: https://ift.tt/G93yixs

    Post summary

    The alert identifies CVE-2026-31898 targeting jsPDF with a PDF Object Injection via FreeText color, providing technical details but no PoC, exploit, or patch information.

    0000046
    335 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-31898 jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of arguments of the `createAnnotation` method allows users to inject arbitrary… https://www.cve.org/CVERecord?id=CVE-2026-31898

    Post summary

    The text discloses CVE‑2026‑31898 for jsPDF, noting an injection flaw in the createAnnotation method before version 4.2.1.

    0000071
    56.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appparalljspdf-node.js-

Explore more