PT-2025-34787 · Parallax · Jspdf

Published

2025-08-26

·

Updated

2025-08-26

·

CVE-2025-57810

CVSS v4.0
8.7
VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

jsPDF is a library to generate PDFs in JavaScript. Prior to 3.0.2, user control of the first argument of the addImage method results in CPU utilization and denial of service. If given the possibility to pass unsanitized image data or URLs to the addImage method, a user can provide a harmful PNG file that results in high CPU utilization and denial of service. The vulnerability was fixed in jsPDF 3.0.2.

Exploit

Fix

RCE

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

CVE-2025-57810

Affected Products

Jspdf