pdfjs-dist is vulnerable to Improper Input Validation
72
High Risk
pdfjs-dist interpolates untrusted PDF data into CSS, XML, and regex-based parsers without adequate validation. Font family names from the document were inserted into @font-face rules and XFA styles without CSS-string serialization, so a crafted name could inject additional CSS rules into the host page. Several parsers also used super-linear regular expressions (XFA font normalization, autolinker email matching, XFA path positions, and XML entity names) and walked AcroForm Parent chains without detecting cycles, so a crafted PDF could stall the viewer or hang the worker. Invalid XML character references aborted parsing entirely. The fix serializes font families as CSS strings, bounds or anchors the affected regexes, breaks cyclic field walks, and keeps invalid character references as literal text.
You are affected if you are using a version that falls within the vulnerable range and your application renders untrusted PDF documents.
pdfjs-dist is vulnerable to Improper Input Validation in versions 0.0.1 - 6.2.108.
Upgrade the pdfjs-dist library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.