Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Yes, a crafted PDF can expose document data in some circumstances—but not every PDF or reader is vulnerable. PortSwigger researcher Gareth Heyes’s 2020 demonstration concerned applications that inserted untrusted input into PDF link annotations without correctly escaping PDF syntax. What happened next depended on the PDF reader and, in some cases, whether the user clicked a link.

What the PDF injection technique does

A PDF uses defined syntax to represent objects, strings and actions. The 2020 technique took advantage of a mistake at the document-generation stage: an application placed attacker-controlled text in a link annotation, but did not safely encode characters that have meaning in PDF syntax. A crafted value could then break out of the intended string and add PDF structures or actions.

Heyes’s paper describes tested examples involving PDF-Lib’s annotation URI construction and jsPDF’s annotation URL property. It is not evidence that every feature, release or current version of either library is vulnerable. The security issue arises when a particular code path treats untrusted input as safe PDF syntax.

How data could be exposed

Once injected PDF actions are present, the PDF reader determines what they can do. Heyes demonstrated reader-specific ways to run JavaScript, submit PDF data and extract document contents. The practical concern is a workflow in which an attacker can influence a link or other annotation in a generated PDF that contains sensitive information.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
BookFactory Security Pass Down Log Book, Wire-O, 100 Pages
  • Made in USA - Proudly produced in Ohio by a Veteran-owned business
  • Comprehensive Coverage: This BookFactory log book includes essential fields such as post/shift, time of change, date, weather conditions, and a designated space for detailed notes. This ensures that all relevant information is captured and easily accessible.
  • Sturdy Cover: The trans-lux cover protects the log book from wear and tear, ensuring its longevity and maintaining the integrity of your recorded data.
  • Essential Security Tool: This log book is an indispensable tool for any organization that values security and accountability. It helps to prevent misunderstandings, improve communication, and ensure a smooth transition between shifts.
  • Wire-O with Trans-lux cover, 100 Pages, Dimensions 8.5" x 11" - (Security-Pass-Down) Reorder SKU: LOG-100-7CW-PP(Security-Pass-Down)

The paper distinguishes Adobe Acrobat from Chrome’s PDFium-based viewer. Their JavaScript capabilities and interaction behavior differ; in the demonstrated Chrome path, a click was required for the relevant submission behavior. The research therefore describes a set of conditional outcomes, not a universal chain in which opening any PDF automatically sends its contents to an attacker.

What the 2020 findings do—and do not—establish

Area What the paper reports What it does not establish
PDF-Lib The tested link-annotation URI path used PDFString.of(...); the paper says parentheses were not escaped in that context, enabling crafted input to introduce PDF syntax. Whether any current PDF-Lib release has the same behavior or remains affected.
jsPDF The paper identifies the annotation url property as an injection point in the tested code path. Whether any current jsPDF release has the same behavior or remains affected.
PDF readers Acrobat and Chrome/PDFium exhibited different JavaScript and interaction behavior in the demonstrations. That every reader supports the same actions or that every attack succeeds without user interaction.
Scale The paper cited more than 52,000 weekly downloads for PDF-Lib and more than 250,000 for jsPDF at the time of the 2020 investigation. Current download totals, the number of affected installations, or a general prevalence rate.

The presentation was listed by PortSwigger for December 10, 2020. These sources document historical research, not a current security advisory or a verified list of fixed package versions. SecurityWeek reported Heyes’s warning that “One simple link can compromise the entire contents of an unknown PDF”; read that as a warning about the demonstrated technique and its context, not a promise that any link compromises any PDF. SecurityWeek’s contemporaneous report and the technical paper provide the original context.

Rank #2
BookFactory Security Incident Report Log Book, Wire-O, 100 Pages
  • Made in USA - Proudly produced in Ohio by a Veteran-owned business
  • This BookFactory log book is for security guards in any sector or business. You can report location, circumstances and report number.
  • There are spaces to log the individual's names address, description and other identifying information. There are also spaces to note others involved, notes, and vehicle information if one was involved
  • Wire-O, 100 Pages, Dimensions 3.5" x 5.25"
  • Reorder SKU: LOG-100-M3CW-PP(Security-Report)

What developers should do

  • Audit annotation inputs. Trace untrusted values into PDF link URI and URL fields, as well as any other fields that can become PDF syntax.
  • Use context-aware encoding. Rely on APIs that correctly encode values for the exact PDF context; ordinary string escaping or validation for a different output format is not a substitute.
  • Keep generation dependencies maintained. Check the current official release notes and security advisories for the versions in use. The 2020 paper does not name a currently fixed version, so it cannot support a specific upgrade recommendation.
  • Test the generated document and its consumers. Review both the PDF-generation path and the reader environments used by people who open the files, especially when generated PDFs contain sensitive information.

A desktop PDF reader or antivirus product does not correct unsafe server-side PDF generation. The core fix is to prevent untrusted values from being interpreted as PDF syntax.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What PDF users should take away

This research does not justify treating all PDFs as automatic data-exfiltration threats. It does show why an unexpectedly generated PDF or an unfamiliar link inside a PDF deserves caution, particularly when the document contains confidential information. For organizations, the more actionable control is to review how PDFs are built and which readers consume them, rather than assuming that a generic reader change resolves a flaw in the generation pipeline.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

PortSwigger’s event listing describes the presentation as covering ways to “escape objects, hijack links, and even execute arbitrary JavaScript” within a PDF. That summary and the technical demonstration describe research presented in 2020, not verified behavior in all current software. PortSwigger’s event announcement identifies the presentation and speaker.

Quick Recap

Bestseller No. 1
BookFactory Security Pass Down Log Book, Wire-O, 100 Pages
BookFactory Security Pass Down Log Book, Wire-O, 100 Pages
Made in USA - Proudly produced in Ohio by a Veteran-owned business
$22.99
Bestseller No. 2
BookFactory Security Incident Report Log Book, Wire-O, 100 Pages
BookFactory Security Incident Report Log Book, Wire-O, 100 Pages
Made in USA - Proudly produced in Ohio by a Veteran-owned business; Wire-O, 100 Pages, Dimensions 3.5" x 5.25"
$9.99
SaleBestseller No. 5
The Web Application Hacker's Handbook: Finding and Exploiting Security Flaws
The Web Application Hacker's Handbook: Finding and Exploiting Security Flaws
Comes with secure packaging; It can be a gift item; Easy to read text
$28.01
Best Value
Sale
The Web Application Hacker's Handbook: Finding and Exploiting Security Flaws
  • Comes with secure packaging
  • It can be a gift item
  • Easy to read text

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.