Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-25630

survey-pdf Upgraded jsPDF Version Due to Security Vulnerability
Back to all
CVE

CVE-2026-25630

survey-pdf Upgraded jsPDF Version Due to Security Vulnerability

The following security vulnerability was identified in jsPDF versions <=3.0.4: Local File Inclusion/Path Traversal.

Impact

Since SurveyJS PDF Generator depends on jsPDF, any project using survey-pdf v1.12.58 and lower or v2.5.4 and lower could be exposed to this vulnerability.

Solution

SurveyJS PDF Generator has upgraded jsPDF to version >= 4.0.0 and included the fix in the following survey-pdf releases:

Action

Users should upgrade survey-pdf in their projects to v1.12.59+ or v2.5.5+ immediately.

Notes

No other survey-pdf dependencies are affected. This update is fully backward-compatible with previous survey-pdf releases.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
0
-
C
H
U
0
-
C
H
U
-

Related Resources

No items found.

References

https://github.com/parallax/jsPDF/security/advisories/GHSA-f8cm-6447-x5h2, https://github.com/surveyjs/survey-pdf/security/advisories/GHSA-h3q6-jfrg-3x6q, https://nvd.nist.gov/vuln/detail/CVE-2026-25630, https://github.com/surveyjs/survey-pdf

Severity

0

CVSS Score
0
10

Basic Information

Ecosystem
Base CVSS
0
EPSS Probability
0%
EPSS Percentile
0%
Introduced Version
0,2.0.0
Fix Available
1.12.59,2.5.5

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading