Back

HIGH

react-pdf's PDF.js vulnerable to arbitrary JavaScript execution upon opening a malicious PDF

Published May 7, 2024

Description

react-pdf displays PDFs in React apps. If PDF.js is used to load a malicious PDF, and PDF.js is configured with `isEvalSupported` set to `true` (which is the default value), unrestricted attacker-controlled JavaScript will be executed in the context of the hosting domain. This vulnerability is fixed in 7.7.3 and 8.0.2.

Affected products

Remediation

No remediation recorded yet.

References (9)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner GitHub_M
Published May 7, 2024
Updated Aug 2, 2024
Reserved May 2, 2024

CISA Vulnrichment

Updated May 7, 2024

NVD

Status Deferred
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner GitHub_M
Published May 7, 2024
Updated Aug 2, 2024