HIGH GitHub
CVE-2026-16633
PDF.js: Arbitrary JavaScript execution upon opening a malicious PDF
### Impact
If PDF.js is used to load a malicious PDF, and PDF.js is configured with `enableScripting` set to true (which is the default value) and no CSP for disallowing script-src, unrestricted attacker-controlled JavaScript will be executed in the context of the hosting domain.
### Patches
### Workarounds
Set `enableScripting` to `false` or set a CSP.
Affected Products
- npm/pdfjs-dist >= 5.6.83, < 6.2.108
References
- https://github.com/advisories/GHSA-hq66-cqwq-w95j
- https://github.com/mozilla/pdf.js/security/advisories/GHSA-hq66-cqwq-w95j
- https://bugzilla.mozilla.org/show_bug.cgi?id=2055885
- https://github.com/advisories/GHSA-hq66-cqwq-w95j
This high severity vulnerability was published on 2026-08-06 via GitHub. Affected: npm/pdfjs-dist >= 5.6.83, < 6.2.108.
vulnfeed aggregates 9207 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.