Vulnerabilities/

@pdfme/common vulnerable to to XSS and Prototype Pollution through its expression evaluation

Severity:
Medium

Description

The expression evaluation feature in pdfme 5.2.0 to 5.4.0 contains critical vulnerabilities allowing sandbox escape leading to XSS and prototype pollution attacks.

Recommendation

Update the @pdfme/common package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@pdfme/common
Anything's wrong? Let us know Last updated on July 10, 2025

This issue is available in SmartScanner Professional

See Pricing