CVE-2026-31938Disclosure(parall / jspdf)

LOWCVSS 6.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch parall jspdf systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of the `options` argument of the `output` function allows attackers to inject arbitrary HTML (such as scripts) into the browser context the created PDF is opened in. The vulnerability can be exploited in the following scenario: the attacker provides values for the output options, for example via a web interface. These values are then passed unsanitized (automatically or semi-automatically) to the attack victim. The victim creates and opens a PDF with the attack vector using one of the vulnerable method overloads inside their browser. The attacker can thus inject scripts that run in the victims browser context and can extract or modify secrets from this context. The vulnerability has been fixed in [email protected]. As a workaround, sanitize user input before passing it to the output method.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • jspdf

Threat summary

  • Patch or workaround signal is available
  • 9 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 8 signals
  • Disclosure: 7 classified signals
  • Peaked 2d ago at 7 mentions (2026-03-18); latest day: 1
  • 9 total mentions across 3 days

Affected systems

Vendors
Products
jspdf

Deep dive

Activity timeline9 mentions / 3d
02457Mentions · 2026-03-18: 7Mentions · 2026-03-19: 1Mentions · 2026-03-20: 1Patch / Workaround · 2026-03-18: 2Patch / Workaround · 2026-03-19: 1Technical Details · 2026-03-18: 6Technical Details · 2026-03-19: 1Technical Details · 2026-03-20: 103-1803-1903-20
Signal classification2 categories
Disclosure
777.8%
Patch
222.2%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-03-187
Disclosure6Patch1
2026-03-191
Patch1
2026-03-201
Disclosure1
Full discourse9 posts
  • Gray Hats@the_yellow_fall
    Patch

    A critical 9.6 CVSS vulnerability in jsPDF (CVE-2026-31938) allows attackers to inject malicious scripts via XSS. Update to version 4.2.1 immediately. #jsPDF #CVE202631938 #XSS #CyberSecurity #InfoSec #JavaScript #WebDev #Vulnerability #AppSec #TechNews https://securityonline.info/invisible-ink-critical-9-6-cvss-jspdf-flaw-xss-cve-2026-31938/ https://t.co/Wd8Do5baHY

    Post summary

    A critical XSS vulnerability (CVE‑2026‑31938) in jsPDF with a 9.6 CVSS score has been disclosed, and users are urged to update to version 4.2.1 immediately to address the issue.

    050173546
    10.7K followersView on X
  • Karma-X@Karma_X_Inc
    Disclosure

    Invisible Ink: Critical 9.6 CVSS jsPDF Flaw Turns Generated Documents into XSS Traps https://securityonline.info/invisible-ink-critical-9-6-cvss-jspdf-flaw-xss-cve-2026-31938/

    Post summary

    The snippet announces CVE-2026-31938, a critical (CVSS 9.6) XSS vulnerability in jsPDF, but does not provide PoC code, exploit details, or patch information.

    0000053
    70 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    HTML Injection (CVE-2026-31938) affects `jsPDF`'s New Window paths, potentially leading to client-side script execution. Review usage for untrusted input. #jsPDF #HTMLInjection #infosec https://www.pulsepatch.io/posts/cve-2026-31938-jspdf-html-injection

    Post summary

    The post announces a new HTML injection CVE in jsPDF that could lead to client‑side script execution, but no exploit, patch, or active attack reports are mentioned.

    0000029
    1 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-31938 - Critical jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of the `options` argument of the `output` function allows attackers to inject arbitrary HTML (such ... https://www.thehackerwire.com/vulnerability/CVE-2026-31938/ https://t.co/GAreIp0RSQ

    Post summary

    A critical vulnerability (CVE‑2026‑31938) in jsPDF permits HTML injection via the `options` argument of `output()` pre‑4.2.1; no PoC, exploit code, patch, or active exploitation is reported.

    0000032
    138 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-31938 📊 Severity: 9.6 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-31938 #CVE-2026-31938 #CVE #Critical  #CyberSecurity #InfoSec https://t.co/zQq1jE16zW

    Post summary

    The tweet announces CVE-2026-31938 with a severity score of 9.6 and indicates it affects multiple, unspecified products, providing only a link to the NVD entry and no further technical or exploit details.

    0000038
    104 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-31938 - jsPDF has HTML Injection in New Window paths Intel Report: https://ift.tt/gYNPCID

    Post summary

    An alert highlights a newly discovered CVE (CVE-2026-31938) affecting jsPDF, describing an HTML injection flaw in the New Window paths, and references an Intel report for more details.

    0000050
    335 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-31938 jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of the `options` argument of the `output` function allows attackers to inject … https://www.cve.org/CVERecord?id=CVE-2026-31938

    Post summary

    CVE-2026-31938 reveals that jsPDF versions before 4.2.1 allow attackers to inject code via the `options` parameter of the `output` function; upgrading to 4.2.1 or later mitigates the risk.

    0000077
    56.7K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-31938: CRITICAL] jsPDF prior to version 4.2.1 allows attackers to inject arbitrary HTML into the browser context via the `options` argument. Upgrade to jspdf@4.2.1 or sanitize user input before pas...#cve,CVE-2026-31938,#cybersecurity https://cvefind.com/CVE-2026-31938

    Post summary

    The post highlights a critical HTML injection flaw in jsPDF before v4.2.1 and recommends upgrading to v4.2.1 or sanitizing input, with no evidence of exploitation or PoC.

    0000057
    603 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-31938: jsPDF has HTML Injection in New ... PDF generation becomes XSS vector when unsanitized options.output() params let attackers inject scripts into victim's b... https://zerodaysignal.com/vulnerability/CVE-2026-31938 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE-2026-31938, describing an XSS vulnerability in jsPDF that allows unsanitized script injection via options.output().

    0000072
    155 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appparalljspdf-node.js-

Explore more