CVE-2026-24737 | parallax jsPDF up to 4.0.x Acroform escape output (GHSA-pqxr-3g65-p328 / WID-SEC-2026-0553)
A vulnerability marked as critical has been reported in parallax jsPDF up to 4.0.x. Impacted is the function AcroformChoiceField.addOption/AcroformChoiceField.setOptions/AcroFormCheckBox.appearanceState/AcroFormRadioButton.appearanceState of the component Acroform Module. The manipulation leads to escaping of output.
This vulnerability is referenced as CVE-2026-24737. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.