CVE-2026-25755 | parallax jsPDF up to 4.1.x addJS code injection (GHSA-9vjf-qc39-jprp)
A vulnerability marked as critical has been reported in parallax jsPDF up to 4.1.x. Affected is the function addJS. Performing a manipulation results in code injection.
This vulnerability is reported as CVE-2026-25755. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.