Description
User control of the argument of the addJS method allows an attacker to inject arbitrary PDF objects into the generated document. By crafting a payload that escapes the JavaScript string delimiter, an attacker can execute malicious actions or alter the document structure, impacting any user who opens the generated PDF.
Recommendation
Update the jspdf package to the latest compatible version. Followings are version details:
- Affected version(s): < 4.2.0
- Patched version(s): 4.2.0
References
Could your website be exposed too?
SmartScanner can check your website for jsPDF has a PDF Object Injection via Unsanitized Input in addJS Method and gives you actionable findings to investigate.
Start a free scanRelated Issues
- jsPDF has a PDF Object Injection via FreeText color - CVE-2026-31898
- i18next-locize-backend has URL Injection via Unsanitized Path Parameters - CVE-2026-41885
- Handlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partial - CVE-2026-33940
- jsPDF has PDF Injection in AcroFormChoiceField that allows Arbitrary JavaScript Execution - CVE-2026-24737


