pdfme is a TypeScript-based PDF generator and React-based UI. The expression evaluation feature in pdfme 5.2.0 to 5.4.0 contains critical vulnerabilities allowing sandbox escape leading to XSS and prototype pollution attacks. This vulnerability is fixed in 5.4.1.
History

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.0003}

epss

{'score': 0.00032}


Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.0003}


Thu, 10 Jul 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Jul 2025 19:00:00 +0000

Type Values Removed Values Added
Description pdfme is a TypeScript-based PDF generator and React-based UI. The expression evaluation feature in pdfme 5.2.0 to 5.4.0 contains critical vulnerabilities allowing sandbox escape leading to XSS and prototype pollution attacks. This vulnerability is fixed in 5.4.1.
Title pdfme has Sandbox Escape and Prototype Pollution vulnerabilities in pdfme expression evaluation
Weaknesses CWE-1321
CWE-79
CWE-94
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-07-10T18:49:22.602Z

Updated: 2025-07-10T19:08:40.237Z

Reserved: 2025-07-07T14:20:38.388Z

Link: CVE-2025-53626

cve-icon Vulnrichment

Updated: 2025-07-10T19:08:31.454Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-10T19:15:27.057

Modified: 2025-07-15T13:14:49.980

Link: CVE-2025-53626

cve-icon Redhat

No data.