Please note that pdfkit 1.0.0 suffers from CVE-2025-26240 (aka GHSA-9g3x-6x24-vf9f )
In JazzCore python-pdfkit 1.0.0, the from_string method enables the execution of JavaScript code within the context of the server application and the exfiltration of local files.
This have been marked as High severity and, ATM, there is no patch.
pdfkit is used in transform.logic
Please note that pdfkit 1.0.0 suffers from CVE-2025-26240 (aka GHSA-9g3x-6x24-vf9f )
This have been marked as High severity and, ATM, there is no patch.
pdfkit is used in
transform.logic