Vulnerability record · CVE-2024-4367 · published 14 May 2024
CVE-2024-4367: PDF.js missing type check allows arbitrary JavaScript execution
Mozilla · Firefox
PDF.js failed to perform a type check when handling fonts, allowing arbitrary JavaScript execution within the PDF.js context. This affects Firefox before 126, Firefox ESR before 115.11, and Thunderbird before 115.11, and also impacts downstream consumers such as Debian and Open-Xchange AppSuite Frontend. Because PDF.js is widely embedded, the flaw matters beyond the listed Mozilla products.
Description
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityHigh CVSS (8.8) with public exploit material and a very high EPSS percentile, though exploitation requires a victim to open a crafted PDF.
What it is
PDF.js failed to perform a type check when handling fonts, allowing arbitrary JavaScript execution within the PDF.js context. This affects Firefox before 126, Firefox ESR before 115.11, and Thunderbird before 115.11, and also impacts downstream consumers such as Debian and Open-Xchange AppSuite Frontend. Because PDF.js is widely embedded, the flaw matters beyond the listed Mozilla products.
Impact
An attacker who gets a crafted PDF opened can execute arbitrary JavaScript in the PDF.js context, which can lead to code execution or data theft depending on the embedding application. The CVSS vector rates high confidentiality, integrity and availability impact.
Attack surface
Reached over the network by delivering a malicious PDF that the victim opens; the CVSS vector requires user interaction (UI:R) and no privileges (PR:N). Any application embedding an affected PDF.js build is a potential entry point.
Exploitation
Not listed in CISA KEV, but EPSS is 0.7066 (99.36th percentile) and public references include an Exploit-DB entry and a vendor research blog, indicating public exploit material exists. No ransomware group usage is documented.
What to do
- Upgrade Firefox to 126 or later, Firefox ESR to 115.11 or later, and Thunderbird to 115.11 or later.
- Update or rebuild any product embedding PDF.js to version 4.2.67 or later, including Open-Xchange AppSuite Frontend and Debian packages.
- Apply the Debian LTS advisories for affected Debian releases.
- Disable or restrict PDF.js-based in-browser PDF rendering where it is not required.
- Treat unsolicited PDF attachments as untrusted and block them at the mail gateway where feasible.
Detection
- Monitor for PDF files containing embedded JavaScript or font objects that trigger PDF.js parsing anomalies.
- Alert on unexpected JavaScript execution or outbound network calls originating from browser or PDF viewer processes.
- Track endpoint and server versions of Firefox, Thunderbird, PDF.js and Open-Xchange AppSuite Frontend against fixed builds.
- Review proxy and DNS logs for connections to domains contacted shortly after a PDF is opened.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2024-4367 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-4367), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.