CVE-2025-68428 is a critical local file inclusion/path traversal vulnerability in jsPDF, a JavaScript PDF generation library, specifically affecting its Node.js builds prior to version 4.0.0. This flaw allows an attacker to retrieve the contents of arbitrary files on the local file system by providing unsanitized paths to methods like loadFile, addImage, html, or addFont, with the file contents then embedded in generated PDFs. Rated with a CVSS score of 7.5 (HIGH), this vulnerability is easily exploitable over the network with low attack complexity and no user interaction required, leading to a high impact on confidentiality. The FAUCET Risk Score is 85/100, indicating significant risk. While there is no evidence of active exploitation (KEV: No), the vulnerability has garnered considerable community attention with 3 mentions and 3 media articles, including reports from BleepingComputer and SecurityWeek, highlighting its critical nature. No public exploit code (Metasploit, Nuclei, ExploitDB) is currently available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.0.0CPE matchmatch criteria | cpe:2.3:a:parall:jspdf:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.