The following security vulnerability was identified in jsPDF versions <=3.0.4: Local File Inclusion/Path Traversal.
Since SurveyJS PDF Generator depends on jsPDF, any project using survey-pdf v1.12.58 and lower or v2.5.4 and lower could be exposed to this vulnerability.
SurveyJS PDF Generator has upgraded jsPDF to version >= 4.0.0 and included the fix in the following survey-pdf releases:
Users should upgrade survey-pdf in their projects to v1.12.59+ or v2.5.5+ immediately.
No other survey-pdf dependencies are affected. This update is fully backward-compatible with previous survey-pdf releases.
{
"cwe_ids": [
"CWE-35",
"CWE-73"
],
"github_reviewed": true,
"github_reviewed_at": "2026-02-04T20:07:34Z",
"nvd_published_at": "2026-02-05T19:15:56Z",
"severity": "CRITICAL"
}