Description
html2pdf.js converts any webpage or element into a printable PDF entirely client-side. Prior to 0.14.0, html2pdf.js contains a cross-site scripting (XSS) vulnerability when given a text source rather than an element. This text is not sufficiently sanitized before being attached to the DOM, allowing malicious scripts to be run on the client browser and risking the confidentiality, integrity, and availability of the page's data. This vulnerability has been fixed in [email protected].
INFO
Published Date :
2026-01-14T16:52:38.372Z
Last Modified :
2026-01-20T18:37:09.279Z
Source :
GitHub_M
AFFECTED PRODUCTS
The following products are affected by CVE-2026-22787 vulnerability.
| Vendors | Products |
|---|---|
| Ekoopmans |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2026-22787.
CVSS Vulnerability Scoring System
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact