Description
pdfmake is an open source client/server side PDF printing in pure JavaScript. In versions up to and including 0.2.5 pdfmake contains an unsafe evaluation of user controlled input. Users of pdfmake are thus subject to arbitrary code execution in the context of the process running the pdfmake code. There are no known fixes for this issue. Users are advised to restrict access to trusted user input.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-48992 | pdfmake is an open source client/server side PDF printing in pure JavaScript. In versions up to and including 0.2.5 pdfmake contains an unsafe evaluation of user controlled input. Users of pdfmake are thus subject to arbitrary code execution in the context of the process running the pdfmake code. There are no known fixes for this issue. Users are advised to restrict access to trusted user input. |
References
History
Mon, 20 Oct 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pdfmake
Pdfmake pdfmake |
|
| CPEs | cpe:2.3:a:pdfmake:pdfmake:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Pdfmake Project
Pdfmake Project pdfmake |
Pdfmake
Pdfmake pdfmake |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-04-22T15:58:39.616Z
Reserved: 2022-11-28T17:27:19.997Z
Link: CVE-2022-46161
No data.
Status : Modified
Published: 2022-12-06T19:15:10.520
Modified: 2025-10-20T15:56:39.987
Link: CVE-2022-46161
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD