pdfjs-dist is vulnerable to Cross-Site Scripting (XSS)
88
High Risk
pdfjs-dist renders XFA form content into the DOM through its XFA display layer. Before the fix this layer creates elements and copies attributes and inline styles directly from the document, without restricting element names, event-handler attributes, or style properties. A crafted PDF containing XFA markup can therefore inject on* event handlers and other active markup that runs as script in the origin of the page hosting the viewer. The fix adds allowlists for permitted elements, attributes, and rich-text styles and drops event-handler attributes so untrusted XFA content can no longer execute JavaScript.
You are affected if you are using a version that falls within the vulnerable range and your application renders untrusted PDF documents without a script-blocking Content Security Policy.
pdfjs-dist is vulnerable to Cross-Site Scripting (XSS) in versions 5.6.83 - 6.1.200.
Upgrade the pdfjs-dist library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant