---
id: CVE-2026-82867
title: >-
  @pdfme/schemas before 5.5.9 contains a cross-site scripting vulnerability in
  the Select schema plugin that fails to sanitize option values before
  interpolating them into HTML via innerHTML
summary: >-
  @pdfme/schemas before 5.5.9 contains a cross-site scripting vulnerability in
  the Select schema plugin that fails to sanitize option values before
  interpolating them into HTML via innerHTML. Attackers can supply malicious
  templates with c…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
published: '2026-08-31'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T15:53:23.707'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82867'
references:
  - url: 'https://github.com/pdfme/pdfme/security/advisories/GHSA-qq9g-96v4-m3cj'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/pdfme-schemas-before-5.5.9-cross-site-scripting-via-select
    label: disclosure@vulncheck.com
  - url: 'https://github.com/pdfme/pdfme/security/advisories/GHSA-qq9g-96v4-m3cj'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.0031
epssPercentile: 0.21241
ingestedAt: '2026-09-10T16:57:28.696Z'
---

## Overview

@pdfme/schemas before 5.5.9 contains a cross-site scripting vulnerability in the Select schema plugin that fails to sanitize option values before interpolating them into HTML via innerHTML. Attackers can supply malicious templates with crafted option values containing HTML and JavaScript to execute arbitrary code in users' browsers.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
