Two widely used JavaScript/TypeScript ecosystem tools disclosed high-severity vulnerabilities that can be triggered by untrusted input during code or document generation. jsPDF patched CVE-2026-24737 (CVSS 8.1), where user-controlled properties in the AcroForm module can enable injection of arbitrary PDF objects (including JavaScript actions) via APIs such as AcroformChoiceField.addOption and AcroFormCheckBox.appearanceState, potentially leading to script execution when a victim opens a crafted PDF. It also patched CVE-2026-24133 (CVSS 8.7), a denial-of-service condition in BMPDecoder reachable through addImage, where a malicious BMP with manipulated width/height headers can force excessive memory allocation and crash the application or browser tab.
Separately, Orval fixed CVE-2026-25141 (CVSS 9.3), a code-injection flaw in its OpenAPI-to-TypeScript client generation pipeline. The issue stems from insufficient sanitization of x-enum-descriptions content embedded into generated block comments; attackers can inject */ to terminate a comment and cause subsequent text to be treated as executable TypeScript/JavaScript. The advisory notes this is a bypass of an earlier fix for CVE-2026-23947, indicating prior mitigations were incomplete; organizations using Orval in CI/CD or consuming third-party OpenAPI specs are at heightened risk if inputs are not strictly trusted and validated.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
The jsPDF maintainers fixed both disclosed vulnerabilities in version 4.1.0 and recommended upgrading to jspdf 4.1.0 or later. As temporary mitigations, they advised sanitizing AcroForm input and validating image data before processing.
Two high-severity jsPDF flaws were disclosed: CVE-2026-24737, which can allow arbitrary PDF object injection through vulnerable AcroForm APIs, and CVE-2026-24133, a denial-of-service issue in BMPDecoder triggered by crafted BMP files with large dimensions. The bugs affect applications that pass unsanitized user input or unvalidated image data into the library.
Following disclosure of CVE-2026-25141, Orval maintainers released patched versions and urged users to upgrade immediately and audit development pipelines for vulnerable releases. The flaw could enable arbitrary code injection when developers generate clients from malicious or compromised OpenAPI specifications.
A critical vulnerability in Orval, tracked as CVE-2026-25141, was disclosed after researchers found attacker-controlled OpenAPI enum descriptions could break out of generated JavaScript comments and inject executable code. The issue was described as an incomplete fix bypass of the earlier CVE-2026-23947, leaving some updated users still vulnerable, including versions starting at 7.19.0.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.