hrynko/vue-pdf-embed

PDF.js Critical Vulnerability

AmmarMohamadIsmaeel opened this issue ยท 5 comments

CVE-2024-4367: JavaScript Flaws Threaten Millions of PDF.js

Please update the pdf js to 4.2.67

Hi @AmmarMohamadIsmaeel @leeobrum

Thanks for bringing this up, I'm on it

@hrynko - any updates? Would love to push out updates for projects using this package. Thank you for all of the hard work!

@hrynko I made a PR with at least a way to minimize the vulnerability until there is a larger updated - #217

PDF.js has been updated to 4.3.136 in v2.0.4