Critical severity10.0NVD Advisory· Published Dec 6, 2022· Updated Jun 17, 2026
CVE-2022-46161
CVE-2022-46161
Description
pdfmake is an open source client/server side PDF printing in pure JavaScript. In versions up to and including 0.2.5 pdfmake contains an unsafe evaluation of user controlled input. Users of pdfmake are thus subject to arbitrary code execution in the context of the process running the pdfmake code. There are no known fixes for this issue. Users are advised to restrict access to trusted user input.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
2- github.com/bpampuch/pdfmake/blob/802813970ac6de68a0bd0931b74150b33da0dd18/dev-playground/server.jsnvdExploitThird Party Advisory
- securitylab.github.com/advisories/GHSL-2022-068_pdfmake/nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.