Cross-Site Scripting Vulnerability in pdfme Schemas by PDFMe
CVE-2026-82865
2.1LOW
What is CVE-2026-82865?
The pdfme schemas prior to version 5.5.10 contain a vulnerability that allows for cross-site scripting via the multiVariableText property panel. This vulnerability arises from the assignment of unsanitized internationalization (i18n) label values to innerHTML. Attackers able to control label overrides through the options.labels can exploit this flaw to inject arbitrary JavaScript. This malicious script executes when users access the Designer and select a multiVariableText field devoid of variable placeholders, resulting in potential unauthorized actions or data exposure during standard operations.
Affected Version(s)
schemas 0 < 5.5.10
schemas 5.5.10
