PT-2026-2926 · Unknown · Html2Pdf.Js

Aydinnyunus

·

Publicado

2026-01-14

·

Atualizado

2026-03-12

·

CVE-2026-22787

CVSS v4.0

8.7

Alta

VetorAV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions html2pdf.js versions prior to 0.14.0
Description html2pdf.js converts webpages or elements into printable PDFs client-side. When provided with a text source instead of an element, versions prior to 0.14.0 do not sufficiently sanitize the text before attaching it to the Document Object Model (DOM). This allows malicious scripts to execute in the client browser, potentially compromising the confidentiality, integrity, and availability of the page’s data. An example attack vector involves using a malicious HTML string containing an img tag with an onerror event handler, such as <img src=x onerror="alert(document.cookie)">, to execute JavaScript code.
Recommendations Versions prior to 0.14.0 should be updated to version 0.14.0, which includes text source sanitization using DOMPurify. As a workaround, users of earlier versions must safely sanitize any text before using it as a source in html2pdf.js.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-22787
GHSA-W8X4-X68C-M6FC

Produtos afetados

Html2Pdf.Js