survey-pdf Upgraded jsPDF Version Due to Security Vulnerability
Critical severity
GitHub Reviewed
Published
Feb 4, 2026
in
surveyjs/survey-pdf
•
Updated Feb 5, 2026
Package
Affected versions
<= 1.12.58
>= 2.0.0, <= 2.5.4
Patched versions
1.12.59
2.5.5
Description
Published to the GitHub Advisory Database
Feb 4, 2026
Reviewed
Feb 4, 2026
Published by the National Vulnerability Database
Feb 5, 2026
Last updated
Feb 5, 2026
The following security vulnerability was identified in jsPDF versions <=3.0.4: Local File Inclusion/Path Traversal.
Impact
Since SurveyJS PDF Generator depends on jsPDF, any project using
survey-pdfv1.12.58 and lower or v2.5.4 and lower could be exposed to this vulnerability.Solution
SurveyJS PDF Generator has upgraded jsPDF to version >= 4.0.0 and included the fix in the following
survey-pdfreleases:Action
Users should upgrade
survey-pdfin their projects to v1.12.59+ or v2.5.5+ immediately.Notes
No other
survey-pdfdependencies are affected. This update is fully backward-compatible with previoussurvey-pdfreleases.References