What happened
A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.
Affected versions
Unknown product: See original advisory Fixed: See vendor advisory.
Why it matters
This source correlation may provide earlier visibility while structured CVE metadata is still being updated.
Detection & mitigation
- Review the original advisory and validate affected versions.
- Apply vendor-provided updates or mitigations when available.
Public PoC references
RepositoryAuthorFirst seenReference
Exploit-DB 52273Firefox ESR 115.11 - PDF.js Arbitrary JavaScript executionMilad karimi2025-04-22VerifiedPoC-in-GitHub · LOURC0D3/CVE-2024-4367-PoCCVE-2024-4367 & CVE-2024-34342 Proof of Concept★ 202LOURC0D32024-05-20CandidatePoC-in-GitHub · s4vvysec/CVE-2024-4367-POCCVE-2024-4367 arbitrary js execution in pdf js★ 57s4vvysec2024-05-20CandidatePoC-in-GitHub · spaceraccoon/detect-cve-2024-4367YARA detection rule for CVE-2024-4367 arbitrary javascript execution in PDF.js★ 11spaceraccoon2024-05-22CandidatePoC-in-GitHub · clarkio/pdfjs-vuln-demoThis project is intended to serve as a proof of concept to demonstrate exploiting the vulnerability in the PDF.js (pdfjs-dist) library reported in CVE-2024-4367★ 4clarkio2024-05-22CandidatePoC-in-GitHub · avalahEE/pdfjs_disable_evalCVE-2024-4367 mitigation for Odoo 14.0★ 1avalahEE2024-05-23CandidatePoC-in-GitHub · Zombie-Kaiser/cve-2024-4367-PoC-fixedPDF.js是由Mozilla维护的基于JavaScript的PDF查看器。此漏洞允许攻击者在打开恶意 PDF 文件后立即执行任意 JavaScript 代码。这会影响所有 Firefox 用户 (<126),因为 Firefox 使用 PDF.js 来显示 PDF 文件,但也严重影响了许多基于 Web 和 Electron 的应用程序,这些应用程序(间接)使用 PDF.js 进行预览功能。★ 12Zombie-Kaiser2024-06-13CandidatePoC-in-GitHub · snyk-labs/pdfjs-vuln-demoThis project is intended to serve as a proof of concept to demonstrate exploiting the vulnerability in the PDF.js (pdfjs-dist) library reported in CVE-2024-4367★ 10snyk-labs2024-06-17CandidatePoC-in-GitHub · UnHackerEnCapital/PDFernetRemoteloPoC - Prueba de Concepto de CVE-2024-4367 en conjunto al CVE-2023-38831 en un solo Script★ 6UnHackerEnCapital2024-06-19CandidatePoC-in-GitHub · Masamuneee/CVE-2024-4367-AnalysisAnalysis and PoC for CVE-2024-4367: arbitrary JavaScript execution (XSS) in PDF.js★ 5Masamuneee2024-09-04CandidatePoC-in-GitHub · m0d0ri205/PDFJSwargame, CVE-2024-4367★ 0m0d0ri2052024-10-08CandidatePoC-in-GitHub · pedrochalegre7/CVE-2024-4367-pdf-sample★ 0pedrochalegre72024-11-06CandidatePoC-in-GitHub · exfil0/WEAPONIZING-CVE-2024-4367CVE-2024-4367 is a critical vulnerability (CVSS 9.8) in PDF.js, allowing arbitrary JavaScript code execution due to insufficient type checks on the FontMatrix object within PDF files.★ 3exfil02025-01-05CandidatePoC-in-GitHub · kabiri-labs/CVE-2024-4367-PoCThis Proof of Concept (PoC) demonstrates the exploitation of the CVE-2024-4367 vulnerability, which involves Cross-Site Scripting (XSS) attacks.★ 1kabiri-labs2025-02-17CandidatePoC-in-GitHub · elamani-drawing/CVE-2024-4367-POC-PDFJSPoC (Proof of Concept) de la CVE-2024-4367 - Vulnérabilité RCE dans libwebp. Démonstration complète incluant : création de payloads, scénarios d'attaque, analyse des risques et serveur Express.js de test.★ 1elamani-drawing2025-03-25CandidatePoC-in-GitHub · VVeakee/CVE-2024-4367★ 0VVeakee2025-04-06CandidatePoC-in-GitHub · BektiHandoyo/cve-pdf-hostPDF host for CVE-2024-4367★ 0BektiHandoyo2025-04-12CandidatePoC-in-GitHub · Bhavyakcwestern/Hacking-pdf.js-vulnerabilityCVE-2024-4367★ 0Bhavyakcwestern2025-04-14CandidatePoC-in-GitHub · PenguinCabinet/CVE-2024-4367-hands-on★ 0PenguinCabinet2025-05-16CandidatePoC-in-GitHub · AnomalousVectors/cve-2024-4367-pocPOC for PDF JS' CVE-2024-4367 vuln★ 1AnomalousVectors2025-06-28CandidatePoC-in-GitHub · 0xr2r/CVE-2024-4367★ 00xr2r2025-08-22CandidatePoC-in-GitHub · 1337rokudenashi/Odoo_PDFjs_CVE-2024-4367.pdfOdoo ≤17 is vulnerable to CVE-2024-4367, allowing arbitrary JavaScript execution via PDF.js.★ 21337rokudenashi2025-08-25CandidatePoC-in-GitHub · xiaoqiesec0x1/CVE-2024-4367-PDF.js-xssCVE-2024-4367–PDF.js-xss★ 0xiaoqiesec0x12026-05-20CandidatePoC-in-GitHub · J1nKsC/CVE-2024-4367_test★ 0J1nKsC2026-06-13CandidatePoC-in-GitHub · veronimo669/pdf.js-CVE-2024-4367SCAN END POC THE CVE-2024-4367★ 1veronimo6692026-06-25CandidatePoC-in-GitHub · yuimamur/CVE-2024-4367-hands-on-01★ 0yuimamur2026-07-27CandidateSource timeline
Discovered through Exploit-DBView source ↗
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.