Impact
pdfme schemas versions older than 5.5.10 contain a cross‑site scripting flaw in the multiVariableText property panel, where the tool assigns unsanitized i18n label values to innerHTML. If an attacker can influence the options.labels configuration, they can inject arbitrary JavaScript that runs whenever a user opens the Designer and selects a multiVariableText field that lacks variable placeholders. The injected code executes in the context of the Designer web page, potentially allowing the attacker to steal data from the designer session or perform additional malicious actions within the user’s local environment.
Affected Systems
The issue affects pdfme schemas releases prior to 5.5.10. Users running those versions should verify their installed version against the supply chain and plan an upgrade if necessary.
Risk and Exploitability
The CVSS score of 2.1 indicates low severity, and the EPSS score is not available, which suggests that exploitation is not currently common. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is local, requiring an attacker to control i18n label overrides through the options.labels setting, so the risk is primarily to users with access to the Design interface who can configure those labels.
OpenCVE Enrichment