Description
react-pdf displays PDFs in React apps. If PDF.js is used to load a malicious PDF, and PDF.js is configured with `isEvalSupported` set to `true` (which is the default value), unrestricted attacker-controlled JavaScript will be executed in the context of the hosting domain. This vulnerability is fixed in 7.7.3 and 8.0.2.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-1513 | react-pdf displays PDFs in React apps. If PDF.js is used to load a malicious PDF, and PDF.js is configured with `isEvalSupported` set to `true` (which is the default value), unrestricted attacker-controlled JavaScript will be executed in the context of the hosting domain. This vulnerability is fixed in 7.7.3 and 8.0.2. |
Github GHSA |
GHSA-87hq-q4gp-9wr4 | react-pdf vulnerable to arbitrary JavaScript execution upon opening a malicious PDF with PDF.js |
References
History
No history.
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T02:51:10.948Z
Reserved: 2024-05-02T06:36:32.436Z
Link: CVE-2024-34342
Updated: 2024-08-02T02:51:10.948Z
Status : Deferred
Published: 2024-05-07T15:15:09.730
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-34342
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA