Security Feed
  1. Archives

Jan 07 2026 Critical jsPDF flaw lets hackers steal secrets via generated PDFs

Source

The jsPDF library for generating PDF documents in JavaScript applications is vulnerable to a critical vulnerability that allows an attacker to steal sensitive data from the local filesystem by including it in generated files. [...]

Posted by Bill Toulas on Wed 07 January 2026 in BleepingComputer.

Tags: Security.

Categories

  1. Ars Technica
  2. AWS Security
  3. BleepingComputer
  4. Brian Krebs
  5. Bruce Schneier
  6. GCP Security
  7. Google Project Zero
  8. The Daily Swig
  9. The Guardian
  10. The Register
  11. Threatpost

Tag cloud

  • Security
  • Uncategorized
  • Security, Identity, & Compliance
  • Security Blog
  • Biz & IT
  • Microsoft
  • Security & Identity
  • AI
  • google
  • CryptoCurrency
  • Announcements
  • A Little Sunshine
  • Foundational (100)
  • Legal
  • privacy
  • Artificial Intelligence
  • Mobile
  • Apple
  • squid
  • Intermediate (200)
  • Advanced (300)
  • Technical How-to
  • hacking
  • The Coming Storm
  • Best Practices

Security Feed. Powered by Pelican and m.css. Code is available on GitLab.