jsPDF Vulnerability Exposes Millions of Developers to Object Injection Attacks

A newly disclosed security flaw in the popular jsPDF library has exposed millions of web developers to PDF Object Injection attacks, allowing remote attackers to embed arbitrary objects and actions into generated PDF documents. Tracked as CVE-2026-25755, the vulnerability affects the addJS method used to embed JavaScript code in PDF files. The issue arises from improper sanitization of user-supplied input in […]

The post jsPDF Vulnerability Exposes Millions of Developers to Object Injection Attacks appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: