FixVibe

// code / spotlight

PDF.js JavaScript Execution Advisory

A vulnerable PDF viewer can turn a malicious document into script execution.

What it is

PDF viewers often sit in document workflows that handle invoices, contracts, resumes, uploads, and support attachments. When PDF.js is in the affected range, rendering a malicious PDF can execute attacker-controlled JavaScript in the hosting page's origin.

How it happens

CVE-2024-4367 affects PDF.js (the `pdfjs-dist` npm package) up to and including 4.1.392 and is fixed in 4.2.67. A crafted PDF can make the viewer run attacker-supplied JavaScript while it renders the document. Because the viewer runs inside your page, that script runs in your app's origin.

What an attacker gets

If an app renders untrusted PDFs with the vulnerable runtime, attacker-controlled script may run in the browser context that hosts the viewer. Depending on the page, that can expose session data, document content, tenant metadata, or actions available to the signed-in user.

// what fixvibe reports

What FixVibe reports

Runs when you connect a GitHub repository, on Pro and above. Each finding shows the file and line, its severity and fix steps you can paste into your AI coding tool.

How to fix it

Upgrade `pdfjs-dist` to 4.2.67 or newer, regenerate the active lockfile, and rebuild every PDF viewer bundle and worker asset. If untrusted PDFs must be rendered before the upgrade rolls out, use `isEvalSupported: false` where compatible as temporary defense-in-depth.

// run it on your own app

Sen yayınlamaya devam et, FixVibe gözcülüğü üstlensin.

Connect a GitHub repo to check its code, dependencies and workflows.

Kaynak kod
198
bu kategoride çalıştırılan testler
modules
155
kaynak kod için özel check’ler
GitHub repos
190+
checks on each connected repo
Connect GitHub →

// latest checks · practical fixes · ship with confidence

PDF.js JavaScript Execution Advisory: what it is and how to fix it · FixVibe