THREAT OPS › Threat News › [GHSA] GHSA-w9hm-4m3m-fxmm (high) — ngx-extended-pdf-viewer bundles a version of pdf.js vulnerable to CVE-2026-16633
[GHSA] GHSA-w9hm-4m3m-fxmm (high) — ngx-extended-pdf-viewer bundles a version of pdf.js vulnerable to CVE-2026-16633
GHSA-w9hm-4m3m-fxmm Severity: high CVE: None
ngx-extended-pdf-viewer bundles a version of pdf.js vulnerable to CVE-2026-16633
ngx-extended-pdf-viewer embeds a fork of Mozilla's pdf.js rather than depending on pdfjs-dist, so this vulnerability is not visible to dependency scanners through package.json.
### Impact Opening a malicious PDF can execute attacker-controlled JavaScript in the context o
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- CVE-2026-16633cve
Original source: https://github.com/advisories/GHSA-w9hm-4m3m-fxmm