CVE-2024-34342 - CVE House
Back to Database
Status published High CVE-2024-34342

react-pdf's PDF.js vulnerable to arbitrary JavaScript execution upon opening a malicious PDF

Vulnerability Description

react-pdf displays PDFs in React apps. If PDF.js is used to load a malicious PDF, and PDF.js is configured with `isEvalSupported` set to `true` (which is the default value), unrestricted attacker-controlled JavaScript will be executed in the context of the hosting domain. This vulnerability is fixed in 7.7.3 and 8.0.2.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-34342

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

react-pdf
Vulnerable Versions:
< 7.7.3, >= 8.0.0, < 8.0.2

Timeline

Official Publish: May 7th, 2024
Last Modified: August 2nd, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L

Weaknesses (CWE)