Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Parallax

Parallax Vendor Cyber Rating & Cyber Score

linktr.ee

Our talented teams shape digital strategies and build new products, services and technologies to drive success. Organisations need to be innovative with digital initiatives - and we understand how challenging they can be to deliver. Our team of experts partner with you to collaborate, deliver and optimise digitally-enabled change. Call us on +44 (0)113 322 6477 or drop us an email: [email protected]


Parallax A.I CyberSecurity Scoring

Parallax
Company Information
Website:https://linktr.ee/parall.ax
Employees number:45
Number of followers:4,376
NAICS:5415
Industry Type:IT Services and IT Consulting
Homepage:linktr.ee
Parallax Risk Score (AI oriented)
Between 750 and 799
logo
ParallaxIT Services and IT Consulting
Updated:
10/03/2026
750/1000
Fair
Baa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Parallax Global Score (TPRM)
xxxx
logo
ParallaxIT Services and IT Consulting
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Parallax
ParallaxFair
Current Score
750Baa (FAIR)
01000
1 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
751Before Incident
MAY 2026
751Before Incident
APRIL 2026
751Before Incident
MARCH 2026
750Before Incident
FEBRUARY 2026
750Before Incident
JANUARY 2026
750Before Incident
DECEMBER 2025
750Before Incident
NOVEMBER 2025
750Before Incident
OCTOBER 2025
750Before Incident
SEPTEMBER 2025
750Before Incident
AUGUST 2025
750Before Incident
JULY 2025
749Before Incident
JANUARY 2025
750Before Incident
Vulnerability
01 Jan 2025Parallax
jsPDF: Critical jsPDF flaw lets hackers steal secrets via generated PDFs

Critical Local File Inclusion Vulnerability in jsPDF Library (CVE-2025-68428)

748After Incident
CRITICAL-2
PAR1767828718
Critical Vulnerability in jsPDF Exposes Sensitive Data via Local File Inclusion A severe vulnerability in the jsPDF library, tracked as CVE-2025-68428 (CVSS 9.2), allows attackers to steal sensitive files from the local filesystem by embedding them in generated PDFs. The flaw stems from a local file inclusion and path traversal issue in jsPDF versions prior to 4.0.0, where unsanitized user input passed to the `loadFile` function enables unauthorized file access. The jsPDF library, widely used for JavaScript-based PDF generation, has over 3.5 million weekly downloads on npm. The vulnerability affects Node.js builds (`dist/jspdf.node.js` and `dist/jspdf.node.min.js`), where the `loadFile` function—used for reading local files—can be exploited if file paths are dynamically controlled by users. Additional methods, including `addImage`, `html`, and `addFont`, are also impacted, as they internally call `loadFile`. Exploitation risk is mitigated if file paths are hardcoded, sourced from trusted configurations, or restricted via allowlists. However, the jsPDF team warns that the vulnerability could be actively exploited given the library’s widespread adoption. The issue was patched in jsPDF 4.0.0, which restricts filesystem access by default and relies on Node.js’s experimental permission model. For full protection, developers are advised to use Node.js 22.13.0, 23.5.0, or 24.0.0 and later, as earlier versions lack stable permission controls. While enabling the `--permission` flag is a suggested workaround, it applies globally to the Node.js process, not just jsPDF. Overly permissive `--allow-fs-read` configurations may also undermine the fix. For older Node.js versions, the jsPDF team recommends sanitizing user-provided paths before passing them to the library. Security firm Endor Labs highlighted the flaw in a technical report, emphasizing the need for strict input validation to prevent exploitation.
INCIDENT DETAILS -
TYPE
Local File Inclusion / Path Traversal
IMPACT
Data Compromised: Sensitive data from local filesystemSystems Affected: Applications using vulnerable versions of jsPDF (Node.js builds)Identity Theft Risk: High (if PII is exposed)Payment Information Risk: High (if payment data is exposed)
DATA BREACH
Type Of Data Compromised: Local filesystem data (potentially sensitive files)Sensitivity Of Data: High (if sensitive files are accessed)Data Exfiltration: Yes (via generated PDFs)Personally Identifiable Information: Possible (if PII files are accessed)

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Parallax ?
?
What was Parallax's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Parallax's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Parallax's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Parallax's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Parallax's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Parallax's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Parallax's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Parallax's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Parallax's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Parallax's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Parallax's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Parallax's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Parallax ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Parallax's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?