TROYANOSYVIRUS
Back to CVEs

CVE-2022-46161

CRITICAL
10.0

Description

pdfmake is an open source client/server side PDF printing in pure JavaScript. In versions up to and including 0.2.5 pdfmake contains an unsafe evaluation of user controlled input. Users of pdfmake are thus subject to arbitrary code execution in the context of the process running the pdfmake code. There are no known fixes for this issue. Users are advised to restrict access to trusted user input.

CVE Details

CVSS v3.1 Score10.0
SeverityCRITICAL
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
Published12/6/2022
Last Modified10/20/2025
Sourcenvd
Honeypot Sightings0

Affected Products

pdfmake:pdfmake

Weaknesses (CWE)

CWE-94

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.