Description
All affected versions <2.0.0 of package jspdf are vulnerable to Cross-site Scripting (XSS). It is possible to inject JavaScript code via the html method.
Remediation
References
https://github.com/MrRio/jsPDF/issues/2795
https://snyk.io/vuln/SNYK-JS-JSPDF-575256
Related Vulnerabilities
CVE-2022-24760 Vulnerability in npm package parse-server
CVE-2022-35980 Vulnerability in maven package org.opensearch.plugin:opensearch-security
CVE-2022-31198 Vulnerability in npm package @openzeppelin/contracts-upgradeable
CVE-2021-23326 Vulnerability in npm package @graphql-tools/git-loader
CVE-2023-24620 Vulnerability in maven package com.esotericsoftware.yamlbeans:yamlbeans