{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/ngx-extended-pdf-viewer--27.0.0-rc.0--29.0.0-rc.3/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["ngx-extended-pdf-viewer (\u003e= 27.0.0-rc.0, \u003c 29.0.0-rc.3)"],"_cs_severities":["high"],"_cs_tags":["supply-chain","vulnerability","web-application","javascript"],"_cs_type":"advisory","_cs_vendors":["Mozilla"],"content_html":"\u003cp\u003eThe ngx-extended-pdf-viewer npm package contains an embedded, vulnerable version of Mozilla's pdf.js (CVE-2026-16633). Because the library bundles the engine directly instead of utilizing a standard dependency, traditional automated dependency scanners often fail to identify the vulnerable component. The vulnerability is triggered when the library processes a maliciously crafted PDF file containing XFA rich text.\u003c/p\u003e\n\u003cp\u003eThe security exposure is linked to the enableXfa feature, which is enabled by default in ngx-extended-pdf-viewer. Successful exploitation allows for arbitrary JavaScript execution within the security context of the page hosting the viewer. This poses a significant risk to web applications that use this library to handle user-uploaded PDF documents. Users are advised to upgrade to version 29.0.0-rc.3 or later, which incorporates the upstream fix from pdf.js 6.2.108.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation leads to unauthorized JavaScript execution in the user's browser, potentially resulting in cross-site scripting (XSS), credential theft, or unauthorized actions performed on behalf of the user within the affected web application. The scope of targeting includes any web application utilizing ngx-extended-pdf-viewer versions between 27.0.0-rc.0 and 29.0.0-rc.3 that allows the processing of untrusted PDF documents.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the ngx-extended-pdf-viewer package to version 29.0.0-rc.3 or higher immediately.\u003c/li\u003e\n\u003cli\u003eIf an immediate upgrade is not feasible, set 'pdfDefaultOptions.enableXfa = false' to disable the vulnerable XFA feature.\u003c/li\u003e\n\u003cli\u003eImplement a Content Security Policy (CSP) that explicitly disallows inline scripts to mitigate the impact of potential exploitation attempts.\u003c/li\u003e\n\u003cli\u003eIntegrate tools capable of parsing CycloneDX SBOMs provided by the package (starting with 29.0.0) to track patching status via VEX statements.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-06T21:29:03Z","date_published":"2026-08-06T21:29:03Z","id":"https://feed.craftedsignal.io/briefs/2026-08-ngx-extended-pdf-viewer-vulnerability/","summary":"The ngx-extended-pdf-viewer library bundles a vulnerable version of pdf.js, allowing attackers to achieve arbitrary JavaScript execution in the context of the host application when processing malicious PDF files with XFA rich text enabled.","title":"Remote Code Execution in ngx-extended-pdf-viewer via CVE-2026-16633","url":"https://feed.craftedsignal.io/briefs/2026-08-ngx-extended-pdf-viewer-vulnerability/"}],"language":"en","title":"CraftedSignal Threat Feed - Ngx-Extended-Pdf-Viewer (\u003e= 27.0.0-Rc.0, \u003c 29.0.0-Rc.3)","version":"https://jsonfeed.org/version/1.1"}