Parallax A.I CyberSecurity Scoring
Parallax
Company Information
Website:https://linktr.ee/parall.ax
Employees number:45
Number of followers:4,376
NAICS:5415
Industry Type:IT Services and IT Consulting
Homepage:linktr.ee
Parallax Risk Score (AI oriented)
Between 750 and 799
ParallaxIT Services and IT Consulting
Updated:
10/03/2026
10/03/2026
750/1000
Fair
Baa
Parallax Global Score (TPRM)
xxxx
ParallaxIT Services and IT Consulting
Score locked

ParallaxFair
Current Score
750Baa (FAIR)
01000
1 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
751
MAY 2026
751
APRIL 2026
751
MARCH 2026
750
FEBRUARY 2026
750
JANUARY 2026
750
DECEMBER 2025
750
NOVEMBER 2025
750
OCTOBER 2025
750
SEPTEMBER 2025
750
AUGUST 2025
750
JULY 2025
749
JANUARY 2025
750
Vulnerability
01 Jan 2025 • Parallax
jsPDF: Critical jsPDF flaw lets hackers steal secrets via generated PDFs
Critical Local File Inclusion Vulnerability in jsPDF Library (CVE-2025-68428)
748
CRITICAL-2
PAR1767828718
Critical Vulnerability in jsPDF Exposes Sensitive Data via Local File Inclusion
A severe vulnerability in the jsPDF library, tracked as CVE-2025-68428 (CVSS 9.2), allows attackers to steal sensitive files from the local filesystem by embedding them in generated PDFs. The flaw stems from a local file inclusion and path traversal issue in jsPDF versions prior to 4.0.0, where unsanitized user input passed to the `loadFile` function enables unauthorized file access.
The jsPDF library, widely used for JavaScript-based PDF generation, has over 3.5 million weekly downloads on npm. The vulnerability affects Node.js builds (`dist/jspdf.node.js` and `dist/jspdf.node.min.js`), where the `loadFile` function—used for reading local files—can be exploited if file paths are dynamically controlled by users. Additional methods, including `addImage`, `html`, and `addFont`, are also impacted, as they internally call `loadFile`.
Exploitation risk is mitigated if file paths are hardcoded, sourced from trusted configurations, or restricted via allowlists. However, the jsPDF team warns that the vulnerability could be actively exploited given the library’s widespread adoption.
The issue was patched in jsPDF 4.0.0, which restricts filesystem access by default and relies on Node.js’s experimental permission model. For full protection, developers are advised to use Node.js 22.13.0, 23.5.0, or 24.0.0 and later, as earlier versions lack stable permission controls. While enabling the `--permission` flag is a suggested workaround, it applies globally to the Node.js process, not just jsPDF. Overly permissive `--allow-fs-read` configurations may also undermine the fix.
For older Node.js versions, the jsPDF team recommends sanitizing user-provided paths before passing them to the library. Security firm Endor Labs highlighted the flaw in a technical report, emphasizing the need for strict input validation to prevent exploitation.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Parallax ??
What was Parallax's A.I Rankiteo Cyber Score in May 2026 ??
What was Parallax's A.I Rankiteo Cyber Score in April 2026 ??
What was Parallax's A.I Rankiteo Cyber Score in March 2026 ??
What was Parallax's A.I Rankiteo Cyber Score in February 2026 ??
What was Parallax's A.I Rankiteo Cyber Score in January 2026 ??
What was Parallax's A.I Rankiteo Cyber Score in December 2025 ??
What was Parallax's A.I Rankiteo Cyber Score in November 2025 ??
What was Parallax's A.I Rankiteo Cyber Score in October 2025 ??
What was Parallax's A.I Rankiteo Cyber Score in September 2025 ??
What was Parallax's A.I Rankiteo Cyber Score in August 2025 ??
What was Parallax's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on Parallax's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Parallax ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Parallax's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?