Vulnerabilities/

Cross-Site Scripting (XSS) via SVG Schema innerHTML Injection in @pdfme/schemas

Severity:
Medium

Description

The SVG schema plugin in @pdfme/schemas renders user-supplied SVG content using container.innerHTML = value without any sanitization, enabling arbitrary JavaScript execution in the user’s browser.

Recommendation

Update the @pdfme/schemas package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@pdfme/schemas
Anything's wrong? Let us know Last updated on March 18, 2026