{"id":"GHSA-wgrm-67xf-hhpq","summary":"PDF.js vulnerable to arbitrary JavaScript execution upon opening a malicious PDF","details":"### Impact\nIf pdf.js is used to load a malicious PDF, and PDF.js is configured with `isEvalSupported` set to `true` (which is the default value), unrestricted attacker-controlled JavaScript will be executed in the context of the hosting domain.\n\n### Patches\nThe patch removes the use of `eval`:\nhttps://github.com/mozilla/pdf.js/pull/18015\n\n### Workarounds\nSet the option `isEvalSupported` to `false`. \n\n### References\nhttps://bugzilla.mozilla.org/show_bug.cgi?id=1893645","aliases":["CVE-2024-4367"],"modified":"2026-07-17T21:04:10.374189817Z","published":"2024-05-07T10:25:08Z","related":["CVE-2024-34342"],"database_specific":{"nvd_published_at":"2024-05-14T18:15:12Z","cwe_ids":["CWE-754"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-05-07T10:25:08Z"},"references":[{"type":"WEB","url":"https://github.com/mozilla/pdf.js/security/advisories/GHSA-wgrm-67xf-hhpq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-4367"},{"type":"WEB","url":"https://github.com/gogs/gogs/issues/7928"},{"type":"WEB","url":"https://github.com/mozilla/pdf.js/pull/18015"},{"type":"WEB","url":"https://github.com/mozilla/pdf.js/commit/85e64b5c16c9aaef738f421733c12911a441cec6"},{"type":"WEB","url":"https://bugzilla.mozilla.org/show_bug.cgi?id=1893645"},{"type":"WEB","url":"https://cert-portal.siemens.com/productcert/html/ssa-827383.html"},{"type":"WEB","url":"https://codeanlabs.com/blog/research/cve-2024-4367-arbitrary-js-execution-in-pdf-js"},{"type":"PACKAGE","url":"https://github.com/mozilla/pdf.js"},{"type":"WEB","url":"https://github.com/mozilla/pdf.js/releases/tag/v4.2.67"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2024/05/msg00010.html"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2024/05/msg00012.html"},{"type":"WEB","url":"https://www.exploit-db.com/exploits/52273"},{"type":"WEB","url":"https://www.mozilla.org/security/advisories/mfsa2024-21"},{"type":"WEB","url":"https://www.mozilla.org/security/advisories/mfsa2024-22"},{"type":"WEB","url":"https://www.mozilla.org/security/advisories/mfsa2024-23"},{"type":"WEB","url":"http://seclists.org/fulldisclosure/2024/Aug/30"}],"affected":[{"package":{"name":"pdfjs-dist","ecosystem":"npm","purl":"pkg:npm/pdfjs-dist"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"4.2.67"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 4.1.392","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-wgrm-67xf-hhpq/GHSA-wgrm-67xf-hhpq.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}