A vulnerability has been reported in jsPDF, which could be exploited by a remote attacker to read arbitrary files and embed their contents into generated PDF documents on the targeted system.
Target Audience:
Organizations and individuals using jsPDF in server-side / Node.js environments
Impact Assessment:
Potential exposure of sensitive data from the underlying host file system due to unauthorized file access and inclusion of file contents in generated PDF documents.
Risk Assessment:
Potential for information disclosure through local file inclusion/path traversal
The information provided herein is on "as is" basis, without warranty of any kind.