CVE-2024-4367

high

Description

A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.

References

https://github.com/stuara1/cpc-pdfjs-poc

https://github.com/Qq1111111111/pentest-i021-poc-1789486727

https://github.com/yuimamur/CVE-2024-4367-hands-on-01

https://github.com/ardakocadoruu/xss-cheatsheet

https://github.com/J1nKsC/CVE-2024-4367_test

https://github.com/Nan-Hack-371/Intern-in-Vulncure

https://github.com/subhashris/driftwatch

https://github.com/xiaoqiesec0x1/CVE-2024-4367-PDF.js-xss

https://cert-portal.siemens.com/productcert/html/ssa-827383.html

https://github.com/1337rokudenashi/Odoo_PDFjs_CVE-2024-4367.pdf

https://github.com/PuddinCat/GithubRepoSpider

https://www.exploit-db.com/exploits/52273

https://github.com/BektiHandoyo/cve-pdf-host

https://github.com/VVeakee/CVE-2024-4367

https://github.com/exfil0/WEAPONIZING-CVE-2024-4367

https://github.com/pedrochalegre7/CVE-2024-4367-pdf-sample

https://github.com/Scivous/CVE-2024-4367-npm

https://github.com/UnHackerEnCapital/PDFernetRemotelo

https://github.com/LOURC0D3/CVE-2024-4367-PoC

https://www.mozilla.org/security/advisories/mfsa2024-23/

https://www.mozilla.org/security/advisories/mfsa2024-22/

https://www.mozilla.org/security/advisories/mfsa2024-21/

https://lists.debian.org/debian-lts-announce/2024/05/msg00012.html

https://lists.debian.org/debian-lts-announce/2024/05/msg00010.html

https://github.com/mozilla/pdf.js/releases/tag/v4.2.67

https://github.com/gogs/gogs/issues/7928

https://codeanlabs.com/blog/research/cve-2024-4367-arbitrary-js-execution-in-pdf-js/

https://bugzilla.mozilla.org/show_bug.cgi?id=1893645

http://seclists.org/fulldisclosure/2024/Aug/30

Details

Source: Mitre, NVD

Published: 2024-05-14

Updated: 2026-05-12

Named Vulnerability: GHSA-wgrm-67xf-hhpq

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 8.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.7066