Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-68428

33
FAUCET Score

CVE-2025-68428 is a critical local file inclusion/path traversal vulnerability in jsPDF, a JavaScript PDF generation library, specifically affecting its Node.js builds prior to version 4.0.0. This flaw allows an attacker to retrieve the contents of arbitrary files on the local file system by providing unsanitized paths to methods like loadFile, addImage, html, or addFont, with the file contents then embedded in generated PDFs. Rated with a CVSS score of 7.5 (HIGH), this vulnerability is easily exploitable over the network with low attack complexity and no user interaction required, leading to a high impact on confidentiality. The FAUCET Risk Score is 85/100, indicating significant risk. While there is no evidence of active exploitation (KEV: No), the vulnerability has garnered considerable community attention with 3 mentions and 3 media articles, including reports from BleepingComputer and SecurityWeek, highlighting its critical nature. No public exploit code (Metasploit, Nuclei, ExploitDB) is currently available.

Impacted Technologies

VendorProductVersion(s)CPE
< 4.0.0CPE matchmatch criteria
cpe:2.3:a:parall:jspdf:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 4.0

9.2CRITICAL

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
NONE
VS Availability
NONE
SS Confidentiality
HIGH
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
2.06%
Probability of exploitation in next 30 days
EPSS Percentile
79.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0206 is in the 64th percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

github_advisorypatch availablevia nvd_reference
View patch
npmpatch availablevia ghsa
Product: jspdfFixed in: 4.0.0
redhatpatch availablevia redhat_api
Product: Red Hat Advanced Cluster Security 4.8Fixed in: advanced-cluster-security/rhacs-main-rhel8:sha256:f96217aeff1a39024700537986dca70ce7e94949c91c3da815dc715ef6588044
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Advanced Cluster Security 4.9Fixed in: advanced-cluster-security/rhacs-main-rhel8:sha256:f49305d1e529f1be7d213f548cc6d49d958ff578eb4e41320250634497a1dfb2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Advanced Cluster Security 4.9Fixed in: advanced-cluster-security/rhacs-main-rhel8:sha256:896bba113fa4ba5eab3bc944d58f7492b55945e2802845edee9362b0682ab419
View patch

Vendor Advisories (2)

redhatCVE-2025-68428Important

jspdf: jsPDF Local File Inclusion/Path Traversal vulnerability

Jan 5, 2026
npmGHSA-f8cm-6447-x5h2critical

jsPDF has Local File Inclusion/Path Traversal vulnerability

Jan 5, 2026

References

access.redhat.com / errata/RHSA-2026:1517
access.redhat.com / errata/RHSA-2026:2350
access.redhat.com / errata/RHSA-2026:2568
access.redhat.com / security/cve/CVE-2025-68428
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2025/cve-2025-68428.json
github.com / parallax/jsPDF/commit/a688c8f479929b24a6543b1fa2d6364abb03066d
Patch
github.com / parallax/jsPDF/releases/tag/v4.0.0
ProductRelease Notes
github.com / parallax/jsPDF/security/advisories/GHSA-f8cm-6447-x5h2
Third Party Advisory