Earlier quoted context omitted.
You're both condescending and incorrect. Bad combination! Zero websites automatically get JavaScript access from me, and many other savvy web users. If PDFs are not subject to these same controls in Firefox, then this could be a security and privacy vulnerability.
PDF is required for JS to run due to code generation in the PDF rendering pipeline facility.
Does the JS run in a true sandbox? Inside, outside, or beside the usual browser sandbox? Are network requests allowed? Filesystem access? Are granular permissions required/available?