A critical vulnerability, tracked as CVE-2025-68428, was discovered in the jsPDF library, which is widely used for generating PDFs in JavaScript applications. The flaw allows attackers to exploit local file inclusion and path traversal in the Node.js build of jsPDF by passing unsanitized paths to the loadFile method, potentially enabling unauthorized access to arbitrary files on the server. Other affected methods include addImage, html, and addFont, with the vulnerability present in the dist/jspdf.node.js and dist/jspdf.node.min.js files. The issue has been addressed in jsPDF version 4.0.0, which restricts file system access by default.
The vulnerability is remotely exploitable and poses a significant risk to applications that allow user-controlled input to these methods. jsPDF recommends updating to version 4.0.0 or later and, for older Node.js versions, sanitizing user-provided paths before use. Additionally, Node.js environments should leverage the --permission flag to further restrict file system access. Organizations using jsPDF in server-side environments are urged to review their implementations and apply the necessary updates or mitigations to prevent potential data breaches or unauthorized file access.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
The vulnerability was fixed in jsPDF version 4.0.0 by restricting file system access by default in the affected Node.js builds. Suggested mitigations for users unable to upgrade included using Node.js permission controls or sanitizing user-supplied paths.
CVE-2025-68428 was identified as a critical local file inclusion and path traversal vulnerability in jsPDF's Node.js builds, allowing attacker-controlled paths in methods such as loadFile to read arbitrary local files and embed their contents in generated PDFs. The issue affects dist/jspdf.node.js and dist/jspdf.node.min.js and is remotely exploitable without user interaction.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.