XSS and Prototype Pollution Vulnerabilities in pdfme PDF Generator
CVE-2025-53626

6.1MEDIUM

Key Information:

Vendor

PDFme

Status
Vendor
CVE Published:
10 July 2025

What is CVE-2025-53626?

The pdfme PDF generator, from versions 5.2.0 to 5.4.0, is susceptible to severe vulnerabilities within the expression evaluation feature. These vulnerabilities can lead to sandbox escape, enabling attackers to execute Cross-Site Scripting (XSS) and prototype pollution attacks. An update to version 5.4.1 effectively addresses and mitigates these risks, ensuring enhanced security for applications using this PDF generation library.

Affected Version(s)

pdfme >= 5.2.0, < 5.4.1

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.