Skip to content
Critical jsPDF Vulnerability Allows File Theft via PDF Generation

Critical jsPDF Vulnerability Allows File Theft via PDF Generation

First seen 7 Jan 2026, 23:31 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

The jsPDF library, used for generating PDF documents in JavaScript applications, has a critical vulnerability that enables attackers to steal sensitive data from the local filesystem. This flaw, tracked as CVE-2025-68428, is a local file inclusion and path traversal issue affecting jsPDF versions prior to 4.0, with a severity score of 9.2. Attackers can exploit this vulnerability by passing unsanitized paths to the file loading mechanism.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 213d ago How this analysis works

More articles in this cluster (4)

Following this threat?

Track Endor Labs and CVE-2025-68428 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed