Headline
GHSA-3jcv-5f9p-2f2p: Cross-site Scripting in electron-pdf
electron-pdf version 20.0.0 allows an external attacker to remotely obtain
arbitrary local files. This is possible because the application does not
validate the HTML content entered by the user.
Cross-site Scripting in electron-pdf
High severity GitHub Reviewed Published Feb 20, 2024 to the GitHub Advisory Database • Updated Feb 21, 2024