pdfjs-dist@4.1.392 vulnerabilities

Generic build of Mozilla's PDF.js library.

Direct Vulnerabilities

Known vulnerabilities in the pdfjs-dist package. This does not include vulnerabilities belonging to this package’s dependencies.

Vulnerability Vulnerable Version
Arbitrary Code Injection

pdfjs-dist is a Portable Document Format (PDF) library that is built with HTML5.

Affected versions of this package are vulnerable to Arbitrary Code Injection in font_loader.js, which passes input to the eval() function when the default isEvalSupported option is in use. An attacker can execute code by convincing a user to open a malicious PDF file.

How to fix Arbitrary Code Injection?

Upgrade pdfjs-dist to version 4.2.67 or higher.