CVE-2026-31938 is a Cross-Site Scripting (XSS) vulnerability affecting the jsPDF library prior to version 4.2.1. It allows attackers to inject arbitrary HTML and scripts into a victim's browser context by manipulating the `output` function's options when a crafted PDF is opened. This medium-severity vulnerability (CVSS 6.1) requires user interaction, enabling script execution to potentially extract or modify sensitive data. While there is no evidence of active exploitation or public exploit code, the vulnerability has garnered some community discussion. The issue is resolved in jsPDF version 4.2.1, and a workaround involves sanitizing user input.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.2.1CPE matchmatch criteria | cpe:2.3:a:parall:jspdf:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.