{"id":"CVE-2024-4367","aliases":["GHSA-wgrm-67xf-hhpq"],"url":"https://o3.security/vulnerability/CVE-2024-4367","summary":"PDF.js vulnerable to arbitrary JavaScript execution upon opening a malicious PDF","details":"### Impact\nIf pdf.js is used to load a malicious PDF, and PDF.js is configured with `isEvalSupported` set to `true` (which is the default value), unrestricted attacker-controlled JavaScript will be executed in the context of the hosting domain.\n\n### Patches\nThe patch removes the use of `eval`:\nhttps://github.com/mozilla/pdf.js/pull/18015\n\n### Workarounds\nSet the option `isEvalSupported` to `false`. \n\n### References\nhttps://bugzilla.mozilla.org/show_bug.cgi?id=1893645","published":"2024-05-14T17:21:23.486Z","modified":"2026-08-14T18:51:36.136740592Z","cvss":{"score":5.6,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"},"epss":{"score":0.7066,"percentile":0.99358,"asOf":"2026-09-15"},"cisaKev":null,"exploitsKnown":17,"affectedPackages":[{"ecosystem":"npm","name":"pdfjs-dist","fixedVersion":"4.2.67"}],"fix":{"url":"https://github.com/mozilla/pdf.js/pull/18015","label":"mozilla/pdf.js#18015"},"references":[{"type":"WEB","url":"http://seclists.org/fulldisclosure/2024/Aug/30"},{"type":"WEB","url":"https://cert-portal.siemens.com/productcert/html/ssa-827383.html"},{"type":"WEB","url":"https://github.com/mozilla/pdf.js/releases/tag/v4.2.67"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2024/05/msg00010.html"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2024/05/msg00012.html"},{"type":"WEB","url":"https://www.exploit-db.com/exploits/52273"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/4xxx/CVE-2024-4367.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-4367"},{"type":"ADVISORY","url":"https://www.mozilla.org/security/advisories/mfsa2024-21/"},{"type":"ADVISORY","url":"https://www.mozilla.org/security/advisories/mfsa2024-22/"},{"type":"ADVISORY","url":"https://www.mozilla.org/security/advisories/mfsa2024-23/"},{"type":"REPORT","url":"https://bugzilla.mozilla.org/show_bug.cgi?id=1893645"},{"type":"REPORT","url":"https://github.com/gogs/gogs/issues/7928"},{"type":"ARTICLE","url":"https://codeanlabs.com/blog/research/cve-2024-4367-arbitrary-js-execution-in-pdf-js/"},{"type":"WEB","url":"https://github.com/mozilla/pdf.js/security/advisories/GHSA-wgrm-67xf-hhpq"},{"type":"WEB","url":"https://github.com/mozilla/pdf.js/pull/18015"},{"type":"WEB","url":"https://github.com/mozilla/pdf.js/commit/85e64b5c16c9aaef738f421733c12911a441cec6"},{"type":"WEB","url":"https://codeanlabs.com/blog/research/cve-2024-4367-arbitrary-js-execution-in-pdf-js"},{"type":"PACKAGE","url":"https://github.com/mozilla/pdf.js"},{"type":"WEB","url":"https://www.mozilla.org/security/advisories/mfsa2024-21"},{"type":"WEB","url":"https://www.mozilla.org/security/advisories/mfsa2024-22"},{"type":"WEB","url":"https://www.mozilla.org/security/advisories/mfsa2024-23"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-14T18:51:36.136740592Z"}}