CVE-2026-82868: @pdfme/schemas before 5.5.9 Cross-Site Scripting via SVG

Published Aug 31, 2026
·
Updated

@pdfme/schemas before 5.5.9 contains a cross-site scripting vulnerability in the SVG schema plugin that renders user-supplied SVG content directly to innerHTML without sanitization. Attackers can inject malicious SVG with embedded scripts, event handlers, or foreignObject elements to execute arbitrary JavaScript in users' browsers when viewing or filling templates.

Affected Software

1 affected component
npm/@pdfme/schemas<5.5.9

Event History

Aug 31, 2026
CVE Published
via MITRE·08:46 AM
Data Sourced
via MITRE·08:46 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Applications using @pdfme/schemas versions before 5.5.9 are exposed when users view or fill templates containing attacker-controlled SVG content handled by the SVG schema plugin.

2

What does an attacker need to exploit it?

An attacker needs to supply malicious SVG content that is incorporated into a template viewed or filled by another user. The attack requires user interaction because the malicious content executes when the affected template is viewed or filled in a browser.

3

What SVG content can trigger script execution?

The affected plugin renders supplied SVG directly through innerHTML without sanitization. Malicious SVG can use embedded scripts, event handlers, or foreignObject elements to execute arbitrary JavaScript.

4

What should teams do to remediate the issue?

Upgrade @pdfme/schemas to version 5.5.9 or later. If upgrading is not immediately possible, do not allow untrusted SVG content in templates processed by the affected SVG schema plugin.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203