Home / Companies / Endor Labs / Blog / Post Details
Content Deep Dive

CVE-2025-68428: Critical Path Traversal in jsPDF

Blog post from Endor Labs

Post Details
Company
Date Published
Author
Peyton Kennedy
Word Count
1,078
Company Posts That Month
10
Language
English
Hacker News Points
-
Post removed?
No
Summary

A critical vulnerability in jsPDF, a popular npm package for generating PDF documents in JavaScript applications, has been identified, allowing attackers to exploit local file inclusion and path traversal by embedding arbitrary files within generated PDFs. This vulnerability, tracked as CVE-2025-68428, affects only the Node.js builds of jsPDF, not browser builds, and can lead to unauthorized disclosure of sensitive data when the affected methods (loadFile, addImage, html, addFont) are passed user-controlled inputs. The issue, discovered by security researcher Kwangwoon Kim and reported through GitHub's security advisory, has been addressed in jsPDF version 4.0.0, which requires Node.js to operate in permission mode to prevent unauthorized file access. However, upgrading poses challenges, as many environments use older Node.js versions lacking stable permission mode support, and enabling this mode may disrupt existing functionalities unless filesystem access patterns are thoroughly mapped. Organizations using jsPDF in server-side environments should prioritize remediation by upgrading to version 4.0.0 and carefully configuring permission settings to mitigate the risk of exploitation.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Vector Search 1 1,668 286 111 +15%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.