CVE-2025-53626
pdfme has Sandbox Escape and Prototype Pollution vulnerabilities in pdfme expression evaluation
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.1EPSS 0.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
10 Jul 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
pdfme is a TypeScript-based PDF generator and React-based UI. The expression evaluation feature in pdfme 5.2.0 to 5.4.0 contains critical vulnerabilities allowing sandbox escape leading to XSS and prototype pollution attacks. This vulnerability is fixed in 5.4.1.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected products
pdfme · pdfmeWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →