CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



GHSA-W9HM-4M3M-FXMM

GHSA-W9HM-4M3M-FXMM: Arbitrary JavaScript Execution via Malicious PDF Parsing in ngx-extended-pdf-viewer

Alon Barad
Alon Barad
Software Engineer

Aug 7, 2026·5 min read·32 visits

Executive Summary (TL;DR)

A high-severity Cross-Site Scripting (XSS) vulnerability exists in ngx-extended-pdf-viewer. By parsing a crafted PDF with XML Forms Architecture (XFA) elements, attackers can bypass sanitizers and execute arbitrary script inside the application context.

The ngx-extended-pdf-viewer library embeds a version of Mozilla's pdf.js that contains vulnerability CVE-2026-16633. This vulnerability allows arbitrary JavaScript execution (XSS) upon rendering a malicious PDF file.

Vulnerability Overview

The ngx-extended-pdf-viewer library embeds a customized, direct-bundled version of Mozilla's pdf.js rendering engine instead of relying on standard external package dependency models. This integration model limits vulnerability detection from automated software composition analysis (SCA) tools, introducing risks associated with hidden dependencies (CWE-1103).

Under default configurations, the application enables XML Forms Architecture (XFA) parsing. This default setting exposes a significant attack surface to malicious actors. When a victim opens a specially crafted PDF document, the engine processes malicious parameters in XFA templates without proper sanitization, leading to client-side code execution.

The vulnerability is tracked under GitHub Security Advisory GHSA-W9HM-4M3M-FXMM, mapping upstream to CVE-2026-16633. It permits unauthenticated remote code execution on the client-side, translating directly to Cross-Site Scripting (XSS) in the context of the hosting web application's origin.

Root Cause Analysis

The root cause of this vulnerability lies in the serialization and encoding logic within two core utility functions in pdf.js: escapePDFName and encodeToXmlString.

The first failure is in the character encoding logic of escapePDFName. When encoding PDF Name objects containing control characters (character codes below 0x10), the system does not zero-pad the resulting hexadecimal notation. This results in characters such as \x05 escaping to #5 instead of #05. An attacker can align syntax-active characters directly following a control character, such as appending c to \x05 to yield #5c. When decoded, this sequence evaluates to \ (backslash), allowing the attacker to escape string literal boundaries within dynamically generated scripts.

The second failure occurs within the encodeToXmlString function, which handles serialization for XML/HTML nodes in XFA forms. The logic incorrectly identifies single-unit Basic Multilingual Plane (BMP) non-characters (such as U+FFFE and U+FFFF) as surrogate pairs. When processing these units, the parser increments its loop index artificially, skipping and dropping the next character in the sequence. By strategically inserting non-characters, attackers can drop sanitization filters, allowing raw script tags and active elements to pass into the rendering boundary.

Code Analysis

The code comparison highlights the parsing flaws and the exact remediations applied in the upstream repository.

In the vulnerable version of escapePDFName, the hex serialization lacks padding:

// Vulnerable code in core_utils.js
function escapePDFName(str) {
  return str.replace(/[\x00-\x1f]/g, (char) => {
    // Bug: No zero-padding for character codes lower than 16
    return "#" + char.charCodeAt(0).toString(16);
  });
}

The patch introduces standard zero-padding to secure character alignment:

// Patched code in core_utils.js
function escapePDFName(str) {
  return str.replace(/[\x00-\x1f]/g, (char) => {
    // Correct: Zero-pads the hex representation to exactly 2 digits
    return "#" + char.charCodeAt(0).toString(16).padStart(2, "0");
  });
}

Additionally, the parsing logic in encodeToXmlString mistakenly handled single-unit non-characters as multi-unit surrogate pairs:

// Vulnerable loop check in core_utils.js
if (char > 0xd7ff && (char < 0xe000 || char > 0xfffd)) {
  // Bug: Incorrect index incrementation on single non-characters
  i++;
}

The fix establishes verified evaluation of high/low surrogate pairs before skipping indexes:

// Patched logic in core_utils.js
const next = str.charCodeAt(i + 1);
if (char >= 0xd800 && char <= 0xdbff && next >= 0xdc00 && next <= 0xdfff) {
  // Correct: Only skips index if a valid low surrogate matches the current high surrogate
  i++;
}

Exploitation Methodology

To execute this attack, an offensive actor must first construct a PDF template containing custom XFA structures with malicious name properties or XML definitions. This payload integrates the character truncation and alignment sequences to bypass HTML validators.

The document is then delivered to a target user who views it inside an application using a vulnerable ngx-extended-pdf-viewer build. Because the viewer has XFA enabled by default, it automatically invokes the parser on the malformed elements.

As the client processes the form templates, the parser reconstructs the corrupted XML sequences into functional markup tags. The payload escapes the script string literal context and runs client-side JavaScript on the hosting platform's domain, granting the attacker unauthenticated execution capability.

Impact Assessment

The impact of this vulnerability is high, threatening both application security boundaries and backend operations that rely on trusted client authorization tokens.

An attacker who successfully exploits this flaw achieves full execution capabilities within the security context of the victim's session. This permits access to session cookies, local storage objects, and API interaction secrets, allowing the attacker to spoof client sessions and query internal APIs.

Because the vulnerability operates entirely on client browsers upon loading a document, detection relies on network-level analysis or file-scanning mechanisms before the payload reaches the application interface.

Remediation and Mitigation

The primary recommendation to resolve this vulnerability is to upgrade ngx-extended-pdf-viewer to version 29.0.0-rc.3 or higher. This release integrates patched core parsing utilities from pdf.js 6.2.108.

If immediate software upgrades are not possible, administrators must disable XFA parsing in the application setup module to remove the default exploit path:

pdfDefaultOptions.enableXfa = false;

Furthermore, implementing a strict Content Security Policy (CSP) that prohibits inline scripts prevents injected DOM markup from executing successfully:

Content-Security-Policy: default-src 'self'; script-src 'self';

Fix Analysis (2)

Technical Appendix

CVSS Score
8.6/ 10
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Affected Systems

ngx-extended-pdf-viewerApplications incorporating vulnerable pdf.js libraries with XML Forms Architecture (XFA) enabled

Affected Versions Detail

Product
Affected Versions
Fixed Version
ngx-extended-pdf-viewer
stephanrauh
>= 27.0.0-rc.0, < 29.0.0-rc.329.0.0-rc.3
AttributeDetail
CWE IDCWE-79 / CWE-1103
Attack VectorNetwork
CVSS Score8.6
ImpactArbitrary JavaScript Execution (XSS)
Exploit Statuspoc
KEV StatusNo

MITRE ATT&CK Mapping

T1190Exploit Public-Facing Application
Initial Access
CWE-79
Cross-site Scripting

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

References & Sources

  • [1]Upstream pdf.js Advisory
  • [2]ngx-extended-pdf-viewer Advisory

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•36 minutes ago•CVE-2026-105643
7.3

CVE-2026-105643: Stored Cross-Site Scripting and Isolation Bypass in Ghost CMS

Stored Cross-Site Scripting (XSS) and origin isolation bypass vulnerability in Ghost CMS versions 6.34.0 through 6.66.1 allows low-privileged staff users to execute arbitrary JavaScript in the context of an administrator session via crafted embed cards.

Alon Barad
Alon Barad
3 views•6 min read
•about 2 hours ago•CVE-2026-105642
8.8

CVE-2026-105642: Remote Code Execution in Ghost CMS via Unsafe SVG Processing during Metadata Scraping

CVE-2026-105642 is a critical remote code execution vulnerability in Ghost CMS, affecting versions 6.56.0 through 6.66.0. The flaw resides in how Ghost's backend handles external image metadata when generating 'Bookmark' cards in the post editor. When a low-privileged staff member inputs a malicious URL, the server fetches and processes an SVG containing an embedded payload, leading to command execution via the underlying, vulnerable image-processing component.

Amit Schendel
Amit Schendel
4 views•6 min read
•about 3 hours ago•CVE-2026-61439
7.5

CVE-2026-61439: Prompt Injection Defense Bypass in PraisonAI InjectionDefense Engine

This report provides a comprehensive technical analysis of CVE-2026-61439 (GHSA-fj8f-m44g-c479), a prompt injection defense bypass vulnerability in the PraisonAI multi-agent framework. In versions prior to 4.6.78, the InjectionDefense scanner threshold defaulted to CRITICAL. This allowed single-vector prompt injections classified as HIGH severity (e.g., direct instruction overrides or financial manipulations) to pass through unblocked, enabling attackers to extract system prompts and execute unauthorized agent tools.

Alon Barad
Alon Barad
5 views•7 min read
•about 4 hours ago•CVE-2026-104890
7.2

CVE-2026-104890: Remote Code Execution via Mixed-Case File Upload Bypass in Kunstmaan CMS MediaBundle

Kunstmaan CMS MediaBundle prior to version 7.3.2 contains a critical file upload vulnerability where case-sensitive extension checks can be bypassed using mixed-case file extensions. Because extension normalization occurs after the validation routine, files with mixed-case executable extensions (such as pHp) bypass checks but are stored with normalized lowercase executable extensions, allowing authenticated administrators to achieve remote code execution.

Amit Schendel
Amit Schendel
10 views•6 min read
•about 5 hours ago•CVE-2026-106443
8.8

CVE-2026-106443: Remote Code Execution in WeasyPrint via Unvalidated Pillow EPS Processing

A critical remote code execution vulnerability was identified in WeasyPrint prior to version 70.0. When compiling HTML containing a malicious Encapsulated PostScript (EPS) graphic on a host with Ghostscript installed, Pillow invokes Ghostscript to process the image, executing arbitrary PostScript commands.

Amit Schendel
Amit Schendel
6 views•8 min read
•about 6 hours ago•CVE-2026-106489
6.5

CVE-2026-106489: Authorization Bypass via Path Traversal in Spotify Backstage TechDocs Backend

An authorization bypass vulnerability in the Spotify Backstage TechDocs backend plugin allows authenticated attackers with access to at least one valid TechDocs site to read arbitrary static documentation from other entities. This occurs due to un-sanitized relative subpaths passing directly to external storage drivers.

Alon Barad
Alon Barad
10 views•7 min read