Vulnerabilities/

jsPDF has HTML Injection in New Window paths

Severity:
High

Description

User control of the options argument of the output function allows attackers to inject arbitrary HTML (such as scripts) into the browser context the created PDF is opened in.

Recommendation

Update the jspdf package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
jspdf
Anything's wrong? Let us know Last updated on March 19, 2026