PT-2025-29133 · Pdfme · Pdfme
Arkark
·
Published
2025-07-10
·
Updated
2025-07-12
·
CVE-2025-53626
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
pdfme versions 5.2.0 through 5.4.0
Description:
The expression evaluation feature in pdfme contains critical vulnerabilities allowing sandbox escape, leading to Cross-Site Scripting (XSS) and prototype pollution attacks. Attackers can bypass the sandbox restrictions to execute arbitrary JavaScript code using methods like
Object.getOwnPropertyDescriptor and Object.getPrototypeOf. The expression evaluator also allows access to prototype accessor methods (lookupGetter, lookupSetter, defineGetter, defineSetter) which can be exploited with Object.assign to pollute the prototype chain. These vulnerabilities can allow attackers to execute arbitrary JavaScript code, steal sensitive information, modify application behavior, and potentially perform actions on behalf of users.Recommendations:
pdfme versions prior to 5.4.1 are affected.
Update to pdfme version 5.4.1 to resolve this issue.
Exploit
Fix
Prototype Pollution
XSS
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pdfme