CVE-2024-4367
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects...
- Published
- May 14, 2024
- Updated
- May 12, 2026
- Assigning CNA
- mozilla
- Evidence observed
- Apr 22, 2025
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HHigh · next 30 days
- Percentile
- 99.4%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
Sources
25Proof-of-concept for CVE-2024-4367 that generates a malicious PDF to exploit arbitrary JavaScript execution in PDF.js.
CVE-2024-4367 & CVE-2024-34342 Proof of Concept
Analysis and PoC for CVE-2024-4367: arbitrary JavaScript execution (XSS) in PDF.js
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.