Intel

AIKIDO-2025-10441

pdf2html is vulnerable to Path Traversal

Path Traversal Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jul 7, 2025

72

High Risk

This Affects:

JSpdf2html
4.1.0 - 4.3.0
Fixed in 4.3.1
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to path traversal due to insufficient validation of the filepath parameter in the generateImage function. An attacker could manipulate filepath to escape the intended directory by using relative paths, allowing arbitrary file read/write operations when processing PDFs or generating images, potentially leading to unauthorized access or system compromise.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

pdf2html is vulnerable to Path Traversal in versions 4.1.0 - 4.3.0.

How to fix this

Upgrade the pdf2html library to a patch version.