15 Total advisories
15 Vulnerabilities
0 Malware

Dependency scanning

Check whether jspdf is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

HIGH 8.1
npm

CVE-2026-24737

jsPDF has PDF Injection in AcroFormChoiceField that allows Arbitrary JavaScript Execution

UNKNOWN
npm

CVE-2026-24040

jsPDF has Shared State Race Condition in addJS Plugin

HIGH 8.1
npm

CVE-2026-25755

jsPDF has a PDF Object Injection via Unsanitized Input in addJS Method

HIGH 7.5
npm

CVE-2025-57810

jsPDF Denial of Service (DoS)

CRITICAL 9.6
npm

CVE-2026-31938

jsPDF has HTML Injection in New Window paths

HIGH 8.1
npm

CVE-2026-31898

jsPDF has a PDF Object Injection via FreeText color

UNKNOWN
npm

CVE-2026-24043

jsPDF Vulnerable to Stored XMP Metadata Injection (Spoofing & Integrity Violation)

HIGH 8.1
npm

CVE-2026-25940

jsPDF has a PDF Injection in AcroForm module allows Arbitrary JavaScript Execution (RadioButton.createOption and "AS" property)

UNKNOWN
npm

CVE-2026-24133

jsPDF Vulnerable to Denial of Service (DoS) via Unvalidated BMP Dimensions in BMPDecoder

UNKNOWN
npm

CVE-2025-68428

jsPDF has Local File Inclusion/Path Traversal vulnerability

UNKNOWN
npm

CVE-2025-29907

jsPDF Bypass Regular Expression Denial of Service (ReDoS)

UNKNOWN
npm

CVE-2026-25535

jsPDF Affected by Client-Side/Server-Side Denial of Service via Malicious GIF Dimensions

MEDIUM 6.1
npm

CVE-2020-7690

Cross-site scripting in jspdf

HIGH 7.5
npm

CVE-2021-23353

jspdf vulnerable to Regular Expression Denial of Service (ReDoS)

MEDIUM 6.1
npm

CVE-2020-7691

Cross-site scripting in jspdf

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes