Denial of Service Vulnerability in jsPDF Library from Parallax
CVE-2025-57810
8.7HIGH
What is CVE-2025-57810?
The jsPDF library, used for generating PDFs in JavaScript, has a vulnerability where unsanitized image data passed to the addImage method can lead to high CPU utilization and denial of service. This happens when a user is allowed to input their own image data or URLs, potentially including harmful PNG files. The issue was addressed in version 3.0.2, providing a secure way to handle image inputs and preventing abuse of CPU resources.
Affected Version(s)
jsPDF < 3.0.2