Bleepingcomputer
Critical jsPDF Vulnerability Allows File Theft via PDF Generation
First seen 7 Jan 2026, 23:31 UTC
•


•51.6
Export
Article Content
Browse articles
The jsPDF library, used for generating PDF documents in JavaScript applications, has a critical vulnerability that enables attackers to steal sensitive data from the local filesystem. This flaw, tracked as CVE-2025-68428, is a local file inclusion and path traversal issue affecting jsPDF versions prior to 4.0, with a severity score of 9.2. Attackers can exploit this vulnerability by passing unsanitized paths to the file loading mechanism.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.