Vulnerability library
Security checkFebruary 03, 2026

jsPDF Vulnerable to Stored XMP Metadata Injection (Spoofing & Integrity Violation)

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Medium severitynpmjspdf

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

User control of the first argument of the addMetadata function allows users to inject arbitrary XML.

If given the possibility to pass unsanitized input to the addMetadata method, a user can inject arbitrary XMP metadata into the generated PDF.

Recommendation

Update the jspdf package to the latest compatible version. Followings are version details:

  • Affected version(s): <= 4.0.0
  • Patched version(s): 4.1.0

References

Could your website be exposed too?

SmartScanner can check your website for jsPDF Vulnerable to Stored XMP Metadata Injection (Spoofing & Integrity Violation) and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated February 03, 2026