---
id: CVE-2026-82868
title: >-
  @pdfme/schemas before 5.5.9 contains a cross-site scripting vulnerability in
  the SVG schema plugin that renders user-supplied SVG content directly to
  innerHTML without sanitization
summary: >-
  @pdfme/schemas before 5.5.9 contains a cross-site scripting vulnerability in
  the SVG schema plugin that renders user-supplied SVG content directly to
  innerHTML without sanitization. Attackers can inject malicious SVG with
  embedded script…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
published: '2026-08-31'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T15:53:23.707'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82868'
references:
  - url: 'https://github.com/pdfme/pdfme/security/advisories/GHSA-87v3-4cfp-cm76'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/pdfme-schemas-before-5.5.9-cross-site-scripting-via-svg
    label: disclosure@vulncheck.com
  - url: 'https://github.com/pdfme/pdfme/security/advisories/GHSA-87v3-4cfp-cm76'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00263
epssPercentile: 0.1615
ingestedAt: '2026-09-10T16:57:28.696Z'
---

## Overview

@pdfme/schemas before 5.5.9 contains a cross-site scripting vulnerability in the SVG schema plugin that renders user-supplied SVG content directly to innerHTML without sanitization. Attackers can inject malicious SVG with embedded scripts, event handlers, or foreignObject elements to execute arbitrary JavaScript in users' browsers when viewing or filling templates.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
