VYPR
Low severity3.3GHSA Advisory· Published Sep 27, 2024· Updated Apr 15, 2026

CVE-2024-9283

CVE-2024-9283

Description

A vulnerability classified as problematic has been found in RelaxedJS ReLaXed up to 0.2.2. Affected is an unknown function of the component Pug to PDF Converter. The manipulation leads to cross site scripting. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

RelaxedJS ReLaXed up to 0.2.2 has a local cross-site scripting vulnerability in its Pug to PDF Converter component, which has been publicly disclosed.

A vulnerability (CVE-2024-9283) has been identified in RelaxedJS ReLaXed, a tool that creates PDF documents using web technologies like HTML, Pug, and JavaScript [1]. The flaw affects version 0.2.2 and earlier, specifically in the Pug to PDF Converter component [2]. The exact function is not specified, but the manipulation leads to cross-site scripting (XSS) [2].

The attack vector is local, meaning an attacker would need local access to the system running ReLaXed to exploit this vulnerability [2]. The exploit has been publicly disclosed, increasing the risk of its use [2]. As a local XSS, the attacker could inject malicious scripts into the PDF generation process, potentially affecting the generated PDF or the local environment.

The impact is classified as problematic with a low severity CVSS v3 score of 3.3 [2]. An attacker with local access could potentially execute arbitrary JavaScript in the context of the PDF generation, which might lead to information disclosure or further local compromise. The vendor, RelaxedJS, has not released a patched version; users should review the repository [1] for updates or apply mitigations such as restricting local access.

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
relaxedjsnpm
<= 0.2.5

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

0

No linked articles in our index yet.