CVE-2026-25755

HIGH

CVSS v3.1: 8.1 · EPSS: 0.0063 (45.8 percentile)

NetworkNo privilegesCode InjectionVendor advisory ref

Source data as of:

At a glance

Severity
HIGH
CVSS
8.1 v3.1 · NVD
EPSS
0.0063 (45.8 percentile) · FIRST.org
CISA KEV
No
Type
Code Injection · NVD CWE
Attack conditions (CVSS vector)
NetworkNo privileges · Source: NVD Vector
Affected vendors
parall
Published
2026-02-19 · Modified: 2026-06-30

CVSS / EPSS / KEV

CVSS v3.1 8.1 / 10 HIGH Source: NVD
EPSS 0.0063 45.8 percentile Source: FIRST.org
CISA KEV No Source: CISA

Source — CVSS: NVD · EPSS: FIRST.org · KEV: CISA. Data & Sources

Description

jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of the argument of the `addJS` method allows an attacker to inject arbitrary PDF objects into the generated document. By crafting a payload that escapes the JavaScript string delimiter, an attacker can execute malicious actions or alter the document structure, impacting any user who opens the generated PDF. The vulnerability has been fixed in [email protected]. As a workaround, escape parentheses in user-provided JavaScript code before passing them to the `addJS` method.

Record details

CVE ID
CVE-2026-25755
CVSS (v3.1)
8.1 (HIGH)
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Exploitability subscore
2.8
Impact subscore
5.2
EPSS
0.0063 (45.8 percentile) — 2026-06-30
CISA KEV
No
Weakness (CWE)
CWE-94, CWE-116
Affected vendors
parall
Affected configurations (CPE)
1
Published
2026-02-19
Modified
2026-06-30
Status
Modified

References

Reference URLs as listed by NVD, grouped by a mechanical match on the link's host/pattern. Labels describe the link type only.