Medium severity5.9NVD Advisory· Published Mar 9, 2021· Updated Jun 17, 2026
CVE-2021-23353
CVE-2021-23353
Description
This affects the package jspdf before 2.3.1. ReDoS is possible via the addImage function.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
jspdfnpm | < 2.3.1 | 2.3.1 |
Affected products
3- jspdf/jspdfdescription
Patches
Vulnerability mechanics
References
9- github.com/MrRio/jsPDF/commit/d8bb3b39efcd129994f7a3b01b632164144ec43envdPatchThird Party AdvisoryWEB
- github.com/MrRio/jsPDF/pull/3091nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-57f3-gghm-9mhcghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-23353ghsaADVISORY
- snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1083289nvdThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1083287nvdThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBMRRIO-1083288nvdThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1083286nvdThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JS-JSPDF-1073626nvdThird Party AdvisoryWEB
News mentions
0No linked articles in our index yet.