pdfjs-dist@1.0.1006 vulnerabilities

Generic build of Mozilla's PDF.js library.

Direct Vulnerabilities

Known vulnerabilities in the pdfjs-dist package. This does not include vulnerabilities belonging to this package’s dependencies.

Cross-site Scripting (XSS)

pdfjs-dist is a Portable Document Format (PDF) library that is built with HTML5.

Affected versions of this package are vulnerable to Cross-site Scripting (XSS). The PDF viewer does not sufficiently sanitize PostScript calculator functions, allowing malicious JavaScript to be injected through a crafted PDF file. This JavaScript can then be run with the permissions of the PDF viewer by its worker.

How to fix Cross-site Scripting (XSS)?

Upgrade pdfjs-dist to version 2.0.943 or higher.