Report
PDF.js is vulnerable to Arbitrary JavaScript Execution in versions prior to 4.2.67. This is due to a missing type check when handling fonts. This makes it possible for authenticated attackers, with contributor-level or above permissions, to execute arbitrary JavaScript if they can successfully trick a user into opening a crafted PDF file.
Score:6.5
Severity:Medium
Version: 0.21.5
There is a patch available in v0.21.6 and we strongly recommend you update to this version as soon as possible.