Skip to content

Upgrade or replace pdfkit #5391

Description

@gamboz

Please note that pdfkit 1.0.0 suffers from CVE-2025-26240 (aka GHSA-9g3x-6x24-vf9f )

In JazzCore python-pdfkit 1.0.0, the from_string method enables the execution of JavaScript code within the context of the server application and the exfiltration of local files.

This have been marked as High severity and, ATM, there is no patch.

pdfkit is used in transform.logic

Metadata

Metadata

Assignees

Labels

dev-readyThis issue has been refined and is ready for development.

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions