CVE-2026-82868 UNKNOWN

CVE-2026-82868

Published: 2026-08-31

Description

@pdfme/schemas before 5.5.9 contains a cross-site scripting vulnerability in the SVG schema plugin that renders user-supplied SVG content directly to innerHTML without sanitization. Attackers can inject malicious SVG with embedded scripts, event handlers, or foreignObject elements to execute arbitrary JavaScript in users' browsers when viewing or filling templates.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…