What the vulnerability does

01Description

All affected versions <2.0.0 of package jspdf are vulnerable to Cross-site Scripting (XSS). It is possible to inject JavaScript code via the html method.

Key dates

02Disclosure timeline

July 6, 2020 CVE published
August 4, 2024 Record updated