Pdfmake Project maintains a JavaScript-based PDF generation library used across web applications for document creation and rendering. The observed vulnerability pattern centers on improper code generation controls, a characteristic risk in templating and dynamic content systems where user input may flow into code execution contexts. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pdfmake Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-11362HIGH Versions of the package pdfmake before 0.3.0-beta.17 are vulnerable to Allocation of Resources Without Limits or Throttling via repeatedly redirect URL in file embedding. An attack | Oct 7, 2025 | 7.5 | 26 | NO | NO |
CVE-2026-26801HIGH Server-Side Request Forgery (SSRF) vulnerability in pdfmake versions 0.3.0-beta.2 through 0.3.5 allows a remote attacker to obtain sensitive information via the src/URLResolver.js | Mar 10, 2026 | 7.5 | 25 | NO | NO |
CVE-2024-25180CRITICAL An issue discovered in pdfmake 0.2.9 allows remote attackers to run arbitrary code via crafted POST request to the /pdf endpoint. NOTE: this is disputed because the behavior of the | Feb 29, 2024 | 9.8 | 25 | NO | NO |
CVE-2022-46161CRITICAL pdfmake is an open source client/server side PDF printing in pure JavaScript. In versions up to and including 0.2.5 pdfmake contains an unsafe evaluation of user controlled input. | Dec 6, 2022 | 9.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pdfmake Project.
Media articles that mention a CVE ID that affects a product developed by Pdfmake Project — matched by CVE ID, not by vendor name.