pdfmake is an open source client/server side PDF printing in pure JavaScript. In versions up to and including 0.2.5 pdfmake contains an unsafe evaluation of user controlled input. Users of pdfmake are thus subject to arbitrary code execution in the context of the process running the pdfmake code. There are no known fixes for this issue. Users are advised to restrict access to trusted user input.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2022-12-06T18:47:00.669Z

Updated: 2024-08-03T14:24:03.395Z

Reserved: 2022-11-28T17:27:19.997Z

Link: CVE-2022-46161

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-12-06T19:15:10.520

Modified: 2023-07-07T19:04:48.333

Link: CVE-2022-46161

cve-icon Redhat

No data.