CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

Critical Path Traversal Flaw in jsPDF Library

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

A critical path traversal vulnerability (CVE-2025-68428) in the jsPDF library allows attackers to steal sensitive data from the local filesystem by including it in generated PDFs. The flaw affects versions before 4.0.0 and is due to unsanitized paths passed to the 'loadFile' function. The issue is mitigated in version 4.0.0 by restricting filesystem access by default.

Timeline

  1. 07.01.2026 23:46 1 articles · 23h ago

    Critical Path Traversal Flaw in jsPDF Library Disclosed

    A critical path traversal vulnerability (CVE-2025-68428) in the jsPDF library allows attackers to steal sensitive data from the local filesystem by including it in generated PDFs. The flaw affects versions before 4.0.0 and is due to unsanitized paths passed to the 'loadFile' function. The issue is mitigated in version 4.0.0 by restricting filesystem access by default.

    Show sources

Information Snippets