Description
User control of the first argument of the addMetadata function allows users to inject arbitrary XML.
If given the possibility to pass unsanitized input to the addMetadata method, a user can inject arbitrary XMP metadata into the generated PDF.
Recommendation
Update the jspdf package to the latest compatible version. Followings are version details:
- Affected version(s): <= 4.0.0
- Patched version(s): 4.1.0
References
Could your website be exposed too?
SmartScanner can check your website for jsPDF Vulnerable to Stored XMP Metadata Injection (Spoofing & Integrity Violation) and gives you actionable findings to investigate.
Start a free scanRelated Issues
- @siteboon/claude-code-ui Vulnerable to Unauthenticated RCE via WebSocket Shell Injection - CVE-2026-31975
- jsPDF has HTML Injection in New Window paths - CVE-2026-31938
- orval MCP client is vulnerable to a code injection attack. - CVE-2026-22785
- OneUptime ClickHouse vulnerable to SQL Injection via unvalidated column identifiers in sort, select, and groupBy paramet - CVE-2026-33142


