Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 31 Aug 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | @pdfme/schemas before 5.5.9 contains a cross-site scripting vulnerability in the Select schema plugin that fails to sanitize option values before interpolating them into HTML via innerHTML. Attackers can supply malicious templates with crafted option values containing HTML and JavaScript to execute arbitrary code in users' browsers. | |
| Title | @pdfme/schemas before 5.5.9 Cross-Site Scripting via Select | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-31T08:46:37.433Z
Reserved: 2026-08-31T08:37:53.170Z
Link: CVE-2026-82867
No data.
Status : Received
Published: 2026-08-31T09:17:07.410
Modified: 2026-08-31T09:17:07.410
Link: CVE-2026-82867
No data.
OpenCVE Enrichment
Updated: 2026-08-31T10:30:17Z
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')