VYPR
Medium severity5.9NVD Advisory· Published Mar 9, 2021· Updated Jun 17, 2026

CVE-2021-23353

CVE-2021-23353

Description

This affects the package jspdf before 2.3.1. ReDoS is possible via the addImage function.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
jspdfnpm
< 2.3.12.3.1

Affected products

3
  • cpe:2.3:a:parall:jspdf:*:*:*:*:*:node.js:*:*
    Range: <2.3.1
  • jspdf/jspdfdescription
  • ghsa-coords
    Range: < 2.3.1

Patches

Vulnerability mechanics

References

9

News mentions

0

No linked articles in our index yet.