CVE-2025-68428: Critical Path Traversal in jsPDF
Blog post from Endor Labs
A critical vulnerability in jsPDF, a popular npm package for generating PDF documents in JavaScript applications, has been identified, allowing attackers to exploit local file inclusion and path traversal by embedding arbitrary files within generated PDFs. This vulnerability, tracked as CVE-2025-68428, affects only the Node.js builds of jsPDF, not browser builds, and can lead to unauthorized disclosure of sensitive data when the affected methods (loadFile, addImage, html, addFont) are passed user-controlled inputs. The issue, discovered by security researcher Kwangwoon Kim and reported through GitHub's security advisory, has been addressed in jsPDF version 4.0.0, which requires Node.js to operate in permission mode to prevent unauthorized file access. However, upgrading poses challenges, as many environments use older Node.js versions lacking stable permission mode support, and enabling this mode may disrupt existing functionalities unless filesystem access patterns are thoroughly mapped. Organizations using jsPDF in server-side environments should prioritize remediation by upgrading to version 4.0.0 and carefully configuring permission settings to mitigate the risk of exploitation.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Vector Search | 1 | 1,668 | 286 | 111 | +15% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.