@pdfme/schemas before 5.5.9 contains a cross-site scripting vulnerability in the Select schema plugin that fails to sanitize option values before interpolating them into HTML via innerHTML. Attackers can supply malicious templates with crafted option values containing HTML and JavaScript to execute arbitrary code in users' browsers.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 31 Aug 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pdfme
Pdfme schemas |
|
| Vendors & Products |
Pdfme
Pdfme schemas |
Mon, 31 Aug 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | @pdfme/schemas before 5.5.9 contains a cross-site scripting vulnerability in the Select schema plugin that fails to sanitize option values before interpolating them into HTML via innerHTML. Attackers can supply malicious templates with crafted option values containing HTML and JavaScript to execute arbitrary code in users' browsers. | |
| Title | @pdfme/schemas before 5.5.9 Cross-Site Scripting via Select | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-31T08:46:37.433Z
Reserved: 2026-08-31T08:37:53.170Z
Link: CVE-2026-82867
No data.
Status : Received
Published: 2026-08-31T09:17:07.410
Modified: 2026-08-31T09:17:07.410
Link: CVE-2026-82867
No data.
OpenCVE Enrichment
Updated: 2026-08-31T21:21:50Z
Weaknesses