Skip to content

fix(deps): vuln jspdf (major → 4.2.1) - #10

Closed
gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
masterfrom
engraver-auto-version-upgrade/major/npm/0-1776937199
Closed

fix(deps): vuln jspdf (major → 4.2.1) #10
gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
masterfrom
engraver-auto-version-upgrade/major/npm/0-1776937199

Conversation

@gh-worker-campaigns-3e9aa4

Copy link
Copy Markdown

Summary: Critical-severity security update — 1 package upgraded (MAJOR changes included)

Manifests changed:

  • . (yarn)

✅ Action Required: Please review the changes below. If they look good, approve and merge this PR.


Updates

Package From To Type Dep Type Vulnerabilities Fixed
jspdf 2.5.2 4.2.1 major Direct 4 CRITICAL, 16 HIGH, 4 MODERATE

Warning

Major Version Upgrade

This update includes major version changes that may contain breaking changes. Please:

  • Review the changelog/release notes for breaking changes
  • Test thoroughly in a staging environment
  • Update any code that depends on changed APIs
  • Ensure all tests pass before merging

Security Details

🚨 Critical & High Severity (20 fixed)
Package CVE Severity Summary Unsafe Version Fixed In
jspdf GHSA-f8cm-6447-x5h2 CRITICAL jsPDF has Local File Inclusion/Path Traversal vulnerability 2.5.2 4.0.0
jspdf CVE-2026-31938 CRITICAL jsPDF has HTML Injection in New Window paths 2.5.2 -
jspdf GHSA-wfv2-pwc8-crg5 CRITICAL jsPDF has HTML Injection in New Window paths 2.5.2 4.2.1
jspdf CVE-2025-68428 CRITICAL jsPDF has Local File Inclusion/Path Traversal vulnerability 2.5.2 -
jspdf GHSA-7x6v-j9x4-qf24 HIGH jsPDF has a PDF Object Injection via FreeText color 2.5.2 4.2.1
jspdf CVE-2026-24133 HIGH jsPDF Affected by Denial of Service (DoS) via Unvalidated BMP Dimensions in BMPDecoder 2.5.2 -
jspdf GHSA-w532-jxjh-hjhj HIGH jsPDF Bypass Regular Expression Denial of Service (ReDoS) 2.5.2 3.0.1
jspdf CVE-2026-24737 HIGH jsPDF has a PDF Injection in AcroFormChoiceField which allows Arbitrary JavaScript Execution 2.5.2 -
jspdf GHSA-9vjf-qc39-jprp HIGH jsPDF has a PDF Object Injection via Unsanitized Input in addJS Method 2.5.2 4.2.0
jspdf CVE-2026-25755 HIGH jsPDF has PDF Object Injection via Unsanitized Input in addJS Method 2.5.2 -
jspdf GHSA-8mvj-3j78-4qmw HIGH jsPDF Denial of Service (DoS) 2.5.2 3.0.2
jspdf CVE-2025-57810 HIGH jsPDF Parsing of Corrupt PNGs Leads to Potential Denial of Service (DoS) 2.5.2 -
jspdf CVE-2026-25940 HIGH jsPDF's PDF Injection in AcroForm module allows Arbitrary JavaScript Execution (RadioButton.createOption and "AS" property) 2.5.2 -
jspdf GHSA-p5xg-68wr-hm3m HIGH jsPDF has a PDF Injection in AcroForm module allows Arbitrary JavaScript Execution (RadioButton.createOption and "AS" property) 2.5.2 4.2.0
jspdf GHSA-67pg-wm7f-q7fj HIGH jsPDF Affected by Client-Side/Server-Side Denial of Service via Malicious GIF Dimensions 2.5.2 4.2.0
jspdf CVE-2026-25535 HIGH jsPDF Affected by Client-Side/Server-Side Denial of Service via Malicious GIF Dimensions 2.5.2 -
jspdf GHSA-95fx-jjr5-f39c HIGH jsPDF Vulnerable to Denial of Service (DoS) via Unvalidated BMP Dimensions in BMPDecoder 2.5.2 4.1.0
jspdf CVE-2025-29907 HIGH jsPDF Bypass Regular Expression Denial of Service (ReDoS) 2.5.2 -
jspdf GHSA-pqxr-3g65-p328 HIGH jsPDF has PDF Injection in AcroFormChoiceField that allows Arbitrary JavaScript Execution 2.5.2 4.1.0
jspdf CVE-2026-31898 HIGH jsPDF has a PDF Object Injection via FreeText color 2.5.2 -
ℹ️ Other Vulnerabilities (4)
Package CVE Severity Summary Unsafe Version Fixed In
jspdf GHSA-vm32-vv63-w422 MODERATE jsPDF Vulnerable to Stored XMP Metadata Injection (Spoofing & Integrity Violation) 2.5.2 4.1.0
jspdf CVE-2026-24043 MODERATE jsPDF Affected by Stored XMP Metadata Injection (Spoofing & Integrity Violation) 2.5.2 -
jspdf CVE-2026-24040 MODERATE jsPDF has a Shared State Race Condition in addJS Plugin 2.5.2 -
jspdf GHSA-cjw8-79x6-5cj4 MODERATE jsPDF has Shared State Race Condition in addJS Plugin 2.5.2 4.1.0

Review Checklist

Extra review is recommended for this update:

  • Review changes for compatibility with your code
  • Check release notes for breaking changes
  • Run integration tests to verify service behavior
  • Test in staging environment before production
  • Monitor key metrics after deployment
  • Approve and merge this PR

Update Mode: Vulnerability Remediation (Critical/High)

🤖 Generated by DataDog Automated Dependency Management System

@gh-worker-campaigns-3e9aa4
gh-worker-campaigns-3e9aa4 Bot deleted the engraver-auto-version-upgrade/major/npm/0-1776937199 branch June 14, 2026 14:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants