A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
CVE-2024-4367
Score elevated to 9.0 because EPSS predicts 73% probability of exploitation within the next 30 days (top 0.6% of all CVEs). NVD baseline CVSS 8.8 retained for reference. Confidence: see factors.
- High exploitation likelihood — EPSS 73%
- Public exploit code is available (ssvc poc, epss top5pct, epss high, public exploit)
A fix is available — apply it.
- CVSS v3
- 8.8
- EG Score
- 9.0(high)
- EG Risk
- 70(Track*)EG Risk 70/100SSVC: Track*
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity90% × 45%Exploitation73% × 40%Automatability0% × 15%Action: Watch closely — could escalate to Attend. - EPSS PROB
- 73%
- EPSS %ILE
- 99%
- KEV
- Not listed
Published
May 14, 2024
Last Modified
May 12, 2026
Advisory Details (9)
Auto-updated May 12, 2026Stored XSS in PDF renderer · Issue #7928 · gogs/gogs · GitHub
https://github.com/gogs/gogs/issues/7928CVE-2024-4367 - Arbitrary JavaScript execution in PDF.js - Codean Labs
https://codeanlabs.com/blog/research/cve-2024-4367-arbitrary-js-execution-in-pdf-js/1893645 - (CVE-2024-4367) Arbitrary Javascript injection in PDF.js through FontMatrix
https://bugzilla.mozilla.org/show_bug.cgi?id=1893645Full Disclosure: OXAS-ADV-2024-0004: OX App Suite Security Advisory
http://seclists.org/fulldisclosure/2024/Aug/30Security Vulnerabilities fixed in Thunderbird 115.11 — Mozilla
https://www.mozilla.org/security/advisories/mfsa2024-23/Security Vulnerabilities fixed in Firefox ESR 115.11 — Mozilla
https://www.mozilla.org/security/advisories/mfsa2024-22/Security Vulnerabilities fixed in Firefox 126 — Mozilla
https://www.mozilla.org/security/advisories/mfsa2024-21/[SECURITY] [DLA 3817-1] thunderbird security update
https://lists.debian.org/debian-lts-announce/2024/05/msg00012.html[SECURITY] [DLA 3815-1] firefox-esr security update
https://lists.debian.org/debian-lts-announce/2024/05/msg00010.htmlVendor Advisories for CVE-2024-4367(20)
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
- RHSA-2026:42062Red Hat Product SecurityHigh
Red Hat Security Advisory: webkit2gtk3 security update
- RHSA-2026:42088Red Hat Product SecurityHigh
Red Hat Security Advisory: webkit2gtk3 security update
- RHSA-2024:3784Red Hat Product SecurityMedium
Red Hat Security Advisory: thunderbird security update
- RHSA-2024:3783Red Hat Product SecurityMedium
Red Hat Security Advisory: firefox security update
- RHSA-2024:3338Red Hat Product SecurityMedium
Red Hat Security Advisory: thunderbird security update
- patch-release-gitlab-17-0-1-releasedGitLab Security
GitLab Patch Release: 17.0.1, 16.11.3, 16.10.6
- RHSA-2024:2913Red Hat Product SecurityHigh
Red Hat Security Advisory: thunderbird security update
- RHSA-2024:2912Red Hat Product SecurityHigh
Red Hat Security Advisory: thunderbird security update
- +12 more
Patch Availability(20)
Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.
Affected Packages
(1 across 1 ecosystem)
npm(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| pdfjs-dist | — | 4.2.67 | — |
Weakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Additional Vendor Advisories
(3)
Vendors that published advisories for this CVE beyond the curated set above. Broader coverage but minimal per-row detail — click through for the original advisory.
Data Freshness Timeline
(refreshed 9× in last 7d / 24× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
- 2026-07-26 14:53 UTCEPSS rescore
- 2026-07-26 14:53 UTCEPSS rescore
- 2026-07-25 14:17 UTCEPSS rescore
- 2026-07-25 14:16 UTCEPSS rescore
- 2026-07-24 14:16 UTCEPSS rescore
- 2026-07-23 02:40 UTCEG score recompute▲ 0.20
- 2026-07-22 14:07 UTCEPSS rescore
- 2026-07-22 14:07 UTCEPSS rescore
- 2026-07-20 17:06 UTCEPSS rescore
- 2026-07-19 02:28 UTCEPSS rescore
- 2026-07-19 02:28 UTCEPSS rescore
- 2026-07-18 10:03 UTCEPSS rescore
- 2026-07-18 10:03 UTCEPSS rescore
- 2026-07-16 17:02 UTCEPSS rescore
- 2026-07-15 16:57 UTCEPSS rescore
- 2026-07-15 16:56 UTCEPSS rescore
- 2026-07-13 06:12 UTCEPSS rescore
- 2026-07-11 08:26 UTCEPSS rescore
- 2026-07-11 05:52 UTCOSV refresh
- 2026-07-09 19:09 UTCEPSS rescore
- 2026-07-09 19:09 UTCEPSS rescore
- 2026-07-05 02:29 UTCEPSS rescore
- 2026-07-04 06:30 UTCEPSS rescore
- 2026-07-01 15:05 UTCEPSS rescore
- 2026-06-27 03:07 UTCEPSS rescore
Show 74 moreShow fewer
- 2026-06-27 03:07 UTCEPSS rescore
- 2026-06-25 13:49 UTCEPSS rescore
- 2026-06-24 14:04 UTCEPSS rescore
- 2026-06-24 14:04 UTCEPSS rescore
- 2026-06-23 21:32 UTCEPSS rescore
- 2026-06-23 21:32 UTCEPSS rescore
- 2026-06-22 12:56 UTCOSV refresh
- 2026-06-21 14:56 UTCEPSS rescore
- 2026-06-21 01:59 UTCEPSS rescore
- 2026-06-21 01:58 UTCEPSS rescore
- 2026-06-18 17:52 UTCEPSS rescore
- 2026-06-18 17:52 UTCEPSS rescore
- 2026-06-17 17:52 UTCEPSS rescore
- 2026-06-17 17:52 UTCEPSS rescore
- 2026-06-16 17:52 UTCEPSS rescore
- 2026-06-16 17:52 UTCEPSS rescore
- 2026-06-15 17:47 UTCEPSS rescore
- 2026-06-14 23:17 UTCEPSS rescore
- 2026-06-13 22:59 UTCEPSS rescore
- 2026-06-13 22:59 UTCEPSS rescore
- 2026-06-13 22:59 UTCEPSS rescore
- 2026-06-12 23:11 UTCEPSS rescore
- 2026-06-12 23:11 UTCEPSS rescore
- 2026-06-11 13:59 UTCEPSS rescore
- 2026-06-10 22:18 UTCEPSS rescore
- 2026-06-10 13:21 UTCEPSS rescore
- 2026-06-08 14:16 UTCEPSS rescore
- 2026-06-08 14:16 UTCEPSS rescore
- 2026-06-07 15:24 UTCEPSS rescore
- 2026-06-07 15:24 UTCEPSS rescore
- 2026-06-06 13:46 UTCEPSS rescore
- 2026-06-06 13:46 UTCEPSS rescore
- 2026-06-05 22:46 UTCEPSS rescore
- 2026-06-05 22:46 UTCEPSS rescore
- 2026-06-05 06:09 UTCEPSS rescore
- 2026-06-05 06:09 UTCEPSS rescore
- 2026-06-04 19:39 UTCOSV refresh
- 2026-06-04 13:11 UTCEPSS rescore
- 2026-06-04 13:11 UTCEPSS rescore
- 2026-06-02 20:12 UTCEPSS rescore
- 2026-05-31 22:30 UTCEPSS rescore
- 2026-05-31 22:30 UTCEPSS rescore
- 2026-05-31 00:16 UTCEPSS rescore
- 2026-05-31 00:16 UTCEPSS rescore
- 2026-05-29 13:43 UTCEPSS rescore
- 2026-05-28 13:44 UTCEPSS rescore
- 2026-05-28 13:44 UTCEPSS rescore
- 2026-05-28 13:44 UTCEPSS rescore
- 2026-05-27 13:40 UTCEPSS rescore
- 2026-05-27 13:40 UTCEPSS rescore
- 2026-05-26 13:43 UTCEPSS rescore
- 2026-05-26 13:43 UTCEPSS rescore
- 2026-05-26 07:18 UTCEPSS rescore
- 2026-05-26 07:18 UTCEPSS rescore
- 2026-05-26 07:18 UTCEPSS rescore
- 2026-05-22 21:16 UTCEPSS rescore
- 2026-05-22 21:16 UTCEPSS rescore
- 2026-05-22 21:16 UTCEPSS rescore
- 2026-05-22 21:16 UTCEPSS rescore
- 2026-05-22 21:16 UTCEPSS rescore
- 2026-05-22 01:57 UTCEG score recompute
- 2026-05-22 01:57 UTCVendor advisory
- 2026-05-21 22:42 UTCEPSS rescore
- 2026-05-20 22:37 UTCEPSS rescore
- 2026-05-20 22:37 UTCEPSS rescore
- 2026-05-20 22:37 UTCEPSS rescore
- 2026-05-20 22:37 UTCEPSS rescore
- 2026-05-20 11:21 UTCEPSS rescore
- 2026-05-20 11:21 UTCEPSS rescore
- 2026-05-20 11:21 UTCEPSS rescore
- 2026-05-20 11:21 UTCEPSS rescore
- 2026-05-18 21:30 UTCEPSS rescore
- 2026-05-18 21:30 UTCEPSS rescore
- 2026-05-18 21:30 UTCEPSS rescore
Publicly available exploits
(10 references)Working exploit code is in the public domain (9 GitHub PoCs) (1 Exploit-DB entry). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
- GitHub PoC1337rokudenashi/Odoo_PDFjs_CVE-2024-4367.pdfFirst seen Aug 25, 2025
Odoo ≤17 is vulnerable to CVE-2024-4367, allowing arbitrary JavaScript execution via PDF.js.
Open source ↗ - Exploit-DBEDB-52273First seen Apr 22, 2025
Firefox ESR 115.11 - PDF.js Arbitrary JavaScript execution
Open source ↗ - GitHub PoCexfil0/WEAPONIZING-CVE-2024-4367First seen Jan 5, 2025
CVE-2024-4367 is a critical vulnerability (CVSS 9.8) in PDF.js, allowing arbitrary JavaScript code execution due to insufficient type checks on the FontMatrix object within PDF files.
Open source ↗ - Open source ↗GitHub PoCMasamuneee/CVE-2024-4367-AnalysisFirst seen Sep 4, 2024
- GitHub PoCUnHackerEnCapital/PDFernetRemoteloFirst seen Jun 19, 2024
PoC - Prueba de Concepto de CVE-2024-4367 en conjunto al CVE-2023-38831 en un solo Script
Open source ↗ - GitHub PoCsnyk-labs/pdfjs-vuln-demoFirst seen Jun 17, 2024
This project is intended to serve as a proof of concept to demonstrate exploiting the vulnerability in the PDF.js (pdfjs-dist) library reported in CVE-2024-4367
Open source ↗ - GitHub PoCZombie-Kaiser/cve-2024-4367-PoC-fixedFirst seen Jun 13, 2024
PDF.js是由Mozilla维护的基于JavaScript的PDF查看器。此漏洞允许攻击者在打开恶意 PDF 文件后立即执行任意 JavaScript 代码。这会影响所有 Firefox 用户 (<126),因为 Firefox 使用 PDF.js 来显示 PDF 文件,但也严重影响了许多基于 Web 和 Electron 的应用程序,这些应用程序(间接)使用 PDF.js 进行预览功能。
Open source ↗ - GitHub PoCspaceraccoon/detect-cve-2024-4367First seen May 22, 2024
YARA detection rule for CVE-2024-4367 arbitrary javascript execution in PDF.js
Open source ↗ - GitHub PoCclarkio/pdfjs-vuln-demoFirst seen May 22, 2024
This project is intended to serve as a proof of concept to demonstrate exploiting the vulnerability in the PDF.js (pdfjs-dist) library reported in CVE-2024-4367
Open source ↗ - GitHub PoCLOURC0D3/CVE-2024-4367-PoCFirst seen May 20, 2024
CVE-2024-4367 & CVE-2024-34342 Proof of Concept
Open source ↗
Frequently asked(5)
What is CVE-2024-4367?
When was CVE-2024-4367 disclosed?
Is CVE-2024-4367 actively exploited?
What is the CVSS score of CVE-2024-4367?
How do I remediate CVE-2024-4367?
Dependency Blast Radius
See which npm, PyPI, Go, and Maven packages are affected by CVE-2024-4367
Is Your Infrastructure Affected by CVE-2024-4367?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.