Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
pdf.js-CVE-2024-4367 — SCAN END POC THE CVE-2024-4367 | Kitploit
Tools/GitHubGitHub/veronimo669/pdf.js-cve-2024-4367
ReconnaissanceVulnerability ScannersExploitationWeb Application ExploitationInformation GatheringPenetration TestingPapers & ResearchLearning & Education
GitHubveronimo669/pdf.js-cve-2024-4367

pdf.js-CVE-2024-4367

SCAN END POC THE CVE-2024-4367

View Repository
1203 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

🚨 CVE-2024-4367 - Universal PDF.js Vulnerability Scanner

⚠️ CRITICAL SECURITY TOOL | Detects CVE-2024-4367 (CVSS 9.8) - PDF.js Remote Code Execution Vulnerability

Version CVSS CVE License

Works on ANY website - Zero configuration required


📋 Table of Contents

  • 📖 Overview
  • ⚡ Quick Start
  • 🔍 What It Detects
  • 🛠️ How It Works
  • 📊 Output Examples
  • 🔒 Remediation Guide
  • 🎯 Exploitation Vectors
  • 🧪 Testing Instructions
  • 📝 Technical Details
  • ⚠️ Legal Disclaimer
  • 📚 References

📖 Overview

CVE-2024-4367 is a critical vulnerability in PDF.js (versions < 4.2.67) that allows arbitrary JavaScript execution via malicious PDF files. This scanner automatically detects vulnerable PDF.js instances on ANY website.

Why This Scanner is Different

  • ✅ Zero configuration - Works on any website instantly
  • ✅ Universal detection - Scans all JavaScript bundles
  • ✅ No dependencies - Pure JavaScript
  • ✅ Proof of Concept - Generates test PDF
  • ✅ Actionable results - Clear remediation steps

The Vulnerability

PDF.js contains a flaw where JavaScript embedded in PDF files is executed without proper sandboxing, allowing attackers to:

  • 🏴‍☠️ Steal authentication tokens from localStorage/sessionStorage
  • 🍪 Exfiltrate session cookies
  • 📁 Access local files (if Electron/desktop app)
  • 🔐 Perform actions as the victim using stolen credentials
  • 🌐 Pivot to internal networks via XSS

⚡ Quick Start

Method 1: Browser Console (Easiest)

  1. Open the target website
  2. Press F12 to open DevTools
  3. Go to the Console tab
  4. Paste the entire scanner script
  5. Press Enter
  6. View the visual results on screen!

Method 2: Bookmarklet

Create a bookmark with this URL:

javascript:(function(){const s=document.createElement('script');s.src='https://cdn.jsdelivr.net/gh/yourusername/CVE-2024-4367-Scanner/scanner.js';document.body.appendChild(s);})();

Method 3: Direct Download

git clone https://github.com/yourusername/CVE-2024-4367-Scanner
cd CVE-2024-4367-Scanner
# Open any website and run the script

🔍 What It Detects

Phase 1: JavaScript Bundle Scanning

  • ✅ PDF.js version detection
  • ✅ Vulnerable version identification (< 4.2.67)
  • ✅ Package.json references
  • ✅ Node_modules paths

Phase 2: PDF Viewer Identification

  • ✅ `` PDF viewers
  • ✅ <embed> elements
  • ✅ <object> data tags
  • ✅ Custom PDF viewer containers
  • ✅ Canvas-based renderers

Phase 3: Exploitation Vectors

  • ✅ URL parameters (?pdf=, ?file=, ?src=)
  • ✅ PDF upload forms
  • ✅ File input fields accepting .pdf
  • ✅ API endpoints with PDF paths

Phase 4: Visual Indicators

  • ✅ Live vulnerability status
  • ✅ Downloadable proof-of-concept PDF
  • ✅ Real-time DOM overlay

🛠️ How It Works

┌─────────────────────────────────────────────────────────────┐
│                    SCAN PROCESS FLOW                        │
├─────────────────────────────────────────────────────────────┤
│                                                             │
│  1. 📚 LOAD SCRIPTS                                         │
│     ├─ External scripts (all <script src="">)              │
│     └─ Inline scripts (all <script> tags)                  │
│                                                             │
│  2. 🔍 EXTRACT PDF.JS VERSION                               │
│     ├─ Pattern matching in code                             │
│     ├─ Package.json detection                               │
│     └─ Node_modules path parsing                            │
│                                                             │
│  3. 🎯 IDENTIFY VULNERABILITY                               │
│     ├─ version < 4.2.67 ? → VULNERABLE                     │
│     └─ version = 2.16.105 ? → VULNERABLE                   │
│                                                             │
│  4. 🖼️ LOCATE VIEWERS                                       │
│     ├─ DOM element scanning                                 │
│     └─ Attribute detection                                 │
│                                                             │
│  5. ⚡ GENERATE POC                                         │
│     ├─ Create test PDF                                      │
│     └─ Provide download link                                │
│                                                             │
│  6. 📊 DISPLAY RESULTS                                      │
│     ├─ Visual overlay                                       │
│     ├─ Console report                                       │
│     └─ Global variable storage                              │
│                                                             │
└─────────────────────────────────────────────────────────────┘

📊 Output Examples

Console Output

╔═══════════════════════════════════════════════════════════════════════════════════╗
║                    CVE-2024-4367 - UNIVERSAL PDF.js SCANNER                         ║
║              Detects vulnerable PDF.js versions and potential exploitation         ║
╚═══════════════════════════════════════════════════════════════════════════════════╝

📚 PHASE 1: Scanning JavaScript Bundles for PDF.js
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
[+] Found 42 external scripts
[+] Found 12 inline scripts
   [1/42] Analyzing: vendor.bundle.js
      → PDF.js indicator found: pdfjs-dist
      ✅ PDF.js version found: 2.16.105
      🚨 VULNERABLE to CVE-2024-4367!

🎯 PHASE 4: Identifying Exploitation Vectors
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
   ⚠️ URL parameter accepts PDF: file=/documents/report.pdf
   ⚠️ PDF upload form found

█████████████████████████████████████████████████████████████████████████████████
                          FINAL SCAN REPORT
█████████████████████████████████████████████████████████████████████████████████

🚨 CRITICAL VULNERABILITY CONFIRMED!
   CVE: CVE-2024-4367
   CVSS: 9.8 (CRITICAL)
   Impact: Arbitrary JavaScript Execution

Visual Overlay

Scanner Overlay

┌─────────────────────────────────────────────────────────────┐
│  CVE-2024-4367 SCAN RESULTS                                │
│  ━━━━━━━━━━━━━━━━━━━━━━━                                    │
│  📍 Target: example.com                                    │
│  📦 PDF.js: 2.16.105                                       │
│  🎯 Vulnerable: YES                                        │
│  📄 Viewers: 3                                             │
│  ⚡ Vectors: 2                                             │
│  ━━━━━━━━━━━━━━━━━━━━━━━                                    │
│  🔴 CRITICAL - Upgrade Required                            │
└─────────────────────────────────────────────────────────────┘

🔒 Remediation Guide

Immediate Actions

1. Upgrade PDF.js (Recommended)

# For Node.js projects
npm install pdfjs-dist@latest

# For CDN usage
# Update to version 4.2.67 or higher

2. Disable JavaScript Execution

// Set this before loading PDF.js
pdfjsLib.GlobalWorkerOptions.disableJavaScript = true;

3. Content Security Policy

Download Tool