CVE-2024-34342 affects react-pdf, a library for rendering PDFs in React applications. When react-pdf uses PDF.js to load a malicious PDF, and PDF.js is operating with isEvalSupported set to true (the default behavior referenced in the advisory), attacker-controlled JavaScript embedded in the PDF can be executed without restriction in the security context of the hosting web application domain. The issue is therefore a script execution flaw triggered by opening a crafted PDF through the vulnerable integration. Fixed releases are 7.7.3 and 8.0.2.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
options.isEvalSupported to false on the react-pdf Document component to disable the vulnerable PDF.js behavior when rendering PDFs. More generally, avoid rendering untrusted PDFs in-browser until the fixed version is deployed.Patch, then assume compromise.
isEvalSupported to false, eliminating the vulnerable PDF.js execution path.1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is primarily a hands-on/lab environment for CVE-2024-4367 in PDF.js, not just a standalone exploit. The core exploit is CVE-2024-4367-PoC/CVE-2024-4367.py, a Python script that generates a malicious PDF by embedding attacker-controlled JavaScript into the PDF FontMatrix structure. When the resulting poc.pdf is opened by a vulnerable PDF.js consumer, the injected JavaScript executes in the PDF.js/hosting origin context. The README explicitly demonstrates both browser-context JavaScript execution (e.g., alert(document.domain)) and, in Electron-style environments, command execution via require('child_process').exec(...). Repository structure: (1) CVE-2024-4367-PoC/ contains the actual exploit generator and exploit README; (2) firefox.py automates downloading specific Firefox Nightly builds and launching poc.pdf to demonstrate vulnerable vs patched behavior; (3) pdfjs_diff_font_renderer.js is a diff artifact showing vulnerable vs fixed font renderer logic; (4) the rest of the repository is largely a PDF.js code/examples tree, including browser examples, Node examples, and a Chromium extension implementation. Those files are mostly supporting context for understanding or reproducing the vulnerability rather than additional exploit stages. Main exploit capability: arbitrary JavaScript execution triggered by opening a crafted PDF file. Secondary capability: potential local command execution in Electron-based hosts where Node integration is exposed. There is no built-in network callback, C2, or exfiltration logic in the exploit itself; payload behavior is entirely user-supplied JavaScript. The exploit is file-delivered and relies on a victim opening the generated PDF in a vulnerable PDF.js environment. The included Firefox launcher script and versioned Nightly download URLs make the repository useful for reproducible testing and patch verification.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.