Skip to content

PDF.js vulnerable to arbitrary JavaScript execution upon opening a malicious PDF

High
nxglabs published GHSA-c67w-jv6m-9m6j Aug 1, 2024

Package

npm pdfjs-dist (npm)

Affected versions

<= 4.1.392

Patched versions

4.2.67

Description

Bumps pdfjs-dist to 4.3.136 and updates ancestor dependency react-pdf. These dependencies need to be updated together.

Updates pdfjs-dist from 3.11.174 to 4.3.136

Commits

Updates react-pdf from 8.0.2 to 9.0.0

Release notes
Commits

Severity

High

CVE ID

No known CVE

Weaknesses

No CWEs

Credits