ZeroHour

CVE-2025-53626

CVSS 3.1
6.1 medium
EPSS
<1%p21
Published
()
Modified
Description

pdfme is a TypeScript-based PDF generator and React-based UI. The expression evaluation feature in pdfme 5.2.0 to 5.4.0 contains critical vulnerabilities allowing sandbox escape leading to XSS and prototype pollution attacks. This vulnerability is fixed in 5.4.1.

Weakness
CWE-79, CWE-94, CWE-1321
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.