In jsPDF prior to 4.2.0, the AcroForm module allows user-controlled properties/methods (notably RadioButton.createOption / appearance state ("AS")-related members such as AcroformChildClass.appearanceState) to be populated with unsanitized input that is incorporated into the generated PDF as raw PDF objects. This enables injection of arbitrary PDF objects, including JavaScript actions, into the output document. In the described exploitation scenario, the injected JavaScript action is triggered when a victim hovers over a radio button option in a PDF viewer that supports JavaScript actions.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository purpose: proof-of-concept for CVE-2026-25940 showing that specially crafted AcroForm radio button appearance streams can inject/trigger PDF JavaScript in vulnerable viewers (notably Foxit). Structure: - README.md: explains the PoC, setup (Node/npm), and a local viewer workflow. - package.json / package-lock.json: Node project pinned to jsPDF 4.1.0. - poc.js (Node entry point): uses jsPDF to generate a PDF containing an AcroForm radio button group with three options. Each option sets a crafted appearanceState string that embeds PDF objects/actions: - opt1: simple JavaScript alert (app.alert('XSS')). - opt2: JavaScript app.launchURL to an external URL; includes commented alternative /Launch action for calc.exe. - opt3: large Foxit-oriented exploit script that performs heap grooming (annotations), forced GC, address leaks (vtable/base), heap pointer leak, memory control via TypedArrays, and a UAF trigger using a getter side-effect. It then constructs a ROP chain intended to call WinExec with a hardcoded UNC path to an executable (\\91\61.2.1.8.10\share\shell.exe). Execution is gated by checks for Windows and Foxit Reader. The script writes test.pdf. - viewer.html (browser harness): loads jsPDF and PDF.js from CDNs, can generate a PoC PDF in-browser and load it into (1) an iframe to exercise the browser/native PDF handler and (2) a PDF.js canvas renderer to compare parsing behavior. It contains an example (commented) fetch() payload to a Pipedream endpoint for observing execution. Overall capabilities: - Generates malicious PDFs that attempt to trigger embedded JavaScript via AcroForm AA actions. - Demonstrates potential escalation toward code execution in Foxit via a memory corruption/ROP chain (still PoC-quality; hardcoded offsets/addresses and environment assumptions).
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.