---
id: CVE-2026-82865
title: >-
  pdfme schemas before 5.5.10 contains a cross-site scripting vulnerability in
  the multiVariableText property panel that assigns unsanitized i18n label
  values to innerHTML
summary: >-
  pdfme schemas before 5.5.10 contains a cross-site scripting vulnerability in
  the multiVariableText property panel that assigns unsanitized i18n label
  values to innerHTML. Attackers who control label overrides through
  options.labels can i…
severity: medium
cvss: 4.4
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
published: '2026-08-31'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T15:53:23.707'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82865'
references:
  - url: 'https://github.com/pdfme/pdfme/security/advisories/GHSA-xgx4-2wgv-4jhm'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/pdfme-schemas-before-5.5.10-cross-site-scripting-via-i18n-label
    label: disclosure@vulncheck.com
  - url: 'https://github.com/pdfme/pdfme/security/advisories/GHSA-xgx4-2wgv-4jhm'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00203
epssPercentile: 0.09063
ingestedAt: '2026-09-10T16:57:28.695Z'
---

## Overview

pdfme schemas before 5.5.10 contains a cross-site scripting vulnerability in the multiVariableText property panel that assigns unsanitized i18n label values to innerHTML. Attackers who control label overrides through options.labels can inject arbitrary JavaScript that executes when users open the Designer and select a multiVariableText field without variable placeholders.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
