Web Hack List

Top 10 winner

Portable Data exFiltration: XSS for PDFs

PDF libraries such as PDF-Lib and jsPDF do not escape parentheses in annotation URIs, so text placed into a generated PDF can close the string and inject new dictionary keys, actions and JavaScript. That gives script execution in Acrobat and Chrome's PDFium, automatic firing on open or close, theft of the document text, and blind SSRF from server-side rendering.

Record

Researcher
Gareth Heyes
Published by
PortSwigger Research
Date
Topic
XSS

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Gareth Heyes, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .