CVE-2026-82868

@pdfme/schemas before 5.5.9 contains a cross-site scripting vulnerability in the SVG schema plugin that renders user-supplied SVG content directly to innerHTML without sanitization. Attackers can inject malicious SVG with embedded scripts, event handlers, or foreignObject elements to execute arbitrary JavaScript in users' browsers when viewing or filling templates.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-31 09:17

Updated : 2026-09-10 15:53


NVD link : CVE-2026-82868

Mitre link : CVE-2026-82868

CVE.ORG link : CVE-2026-82868


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')