Toggle light / dark theme

Critical jsPDF flaw lets hackers steal secrets via generated PDFs

The jsPDF library for generating PDF documents in JavaScript applications is vulnerable to a critical vulnerability that allows an attacker to steal sensitive data from the local filesystem by including it in generated files.

The flaw is a local file inclusion and path traversal that allows passing unsanitized paths to the file loading mechanism (loadFile) in jsPDF versions before 4.0. It is tracked as CVE-2025–68428 and received a severity score of 9.2.

The jsPDF library is a widely adopted package with more than 3.5 million weekly downloads in the npm registry.

US engineers are defying gravity by cutting through entire mountains in the Andes and creating giant roads attached to extreme cliffs, deep tunnels, and suspended pillars

US engineers are defying gravity by cutting through mountains in the Andes and creating giant roads with tunnels, suspended pillars, and colossal machines.

How does the small molecule NVP-BHG712 protect against pulmonary fibrosis in mice?

Mohit Kapoor & team identify EphB4 receptor as a crucial mediator of pulmonary fibrosis that regulates genes involved in ECM organization, ER cargo concentration and protein trafficking in fibroblasts.


4Department of Epidemiology and Biostatistics, Western University, London, Ontario, Canada.

5Department of Biostatistics, University Health Network, Toronto, Ontario, Canada.

6Dalla Lana School of Public Health and Department of Statistical Sciences, University of Toronto, Toronto, Ontario, Canada.

/* */