← back
CVE-2025-53626

pdfme has Sandbox Escape and Prototype Pollution vulnerabilities in pdfme expression evaluation

CVSS 6.1 MEDIUMEPSS 0.3%CWE-1321CWE-79CWE-94
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.1EPSS 0.3%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
10 Jul 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
pdfme is a TypeScript-based PDF generator and React-based UI. The expression evaluation feature in pdfme 5.2.0 to 5.4.0 contains critical vulnerabilities allowing sandbox escape leading to XSS and prototype pollution attacks. This vulnerability is fixed in 5.4.1.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected products
pdfme · pdfme

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →