15 Total advisories
15 Vulnerabilities
0 Malware
Dependency scanning
Check whether jspdf is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 8.1
CVE-2026-24737
jsPDF has PDF Injection in AcroFormChoiceField that allows Arbitrary JavaScript Execution
UNKNOWN
CVE-2026-24040
jsPDF has Shared State Race Condition in addJS Plugin
HIGH 8.1
CVE-2026-25755
jsPDF has a PDF Object Injection via Unsanitized Input in addJS Method
HIGH 7.5
CVE-2025-57810
jsPDF Denial of Service (DoS)
CRITICAL 9.6
CVE-2026-31938
jsPDF has HTML Injection in New Window paths
HIGH 8.1
CVE-2026-31898
jsPDF has a PDF Object Injection via FreeText color
UNKNOWN
CVE-2026-24043
jsPDF Vulnerable to Stored XMP Metadata Injection (Spoofing & Integrity Violation)
HIGH 8.1
CVE-2026-25940
jsPDF has a PDF Injection in AcroForm module allows Arbitrary JavaScript Execution (RadioButton.createOption and "AS" property)
UNKNOWN
CVE-2026-24133
jsPDF Vulnerable to Denial of Service (DoS) via Unvalidated BMP Dimensions in BMPDecoder
UNKNOWN
CVE-2025-68428
jsPDF has Local File Inclusion/Path Traversal vulnerability
UNKNOWN
CVE-2025-29907
jsPDF Bypass Regular Expression Denial of Service (ReDoS)
UNKNOWN
CVE-2026-25535
jsPDF Affected by Client-Side/Server-Side Denial of Service via Malicious GIF Dimensions
MEDIUM 6.1
CVE-2020-7690
Cross-site scripting in jspdf
HIGH 7.5
CVE-2021-23353
jspdf vulnerable to Regular Expression Denial of Service (ReDoS)
MEDIUM 6.1
CVE-2020-7691
Cross-site scripting in jspdf
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes