CVE-2025-53626

pdfme is a TypeScript-based PDF generator and React-based UI. The expression evaluation feature in pdfme 5.2.0 to 5.4.0 contains critical vulnerabilities allowing sandbox escape leading to XSS and prototype pollution attacks. This vulnerability is fixed in 5.4.1.
Configurations

No configuration.

History

15 Jul 2025, 13:14

Type Values Removed Values Added
Summary
  • (es) pdfme es un generador de PDF basado en TypeScript y una interfaz de usuario basada en React. La función de evaluación de expresiones de pdfme 5.2.0 a 5.4.0 contiene vulnerabilidades críticas que permiten escapar de la zona protegida, lo que provoca ataques XSS y de contaminación de prototipos. Esta vulnerabilidad se corrige en la versión 5.4.1.

10 Jul 2025, 20:15

Type Values Removed Values Added
References () https://github.com/pdfme/pdfme/security/advisories/GHSA-54xv-94qv-2gfg - () https://github.com/pdfme/pdfme/security/advisories/GHSA-54xv-94qv-2gfg -

10 Jul 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-10 19:15

Updated : 2025-07-15 13:14


NVD link : CVE-2025-53626

Mitre link : CVE-2025-53626

CVE.ORG link : CVE-2025-53626


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-94

Improper Control of Generation of Code ('Code Injection')

CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')