Please have a look at the following comments: https://bugzilla.mozilla.org/show_bug.cgi?id=965003#c5 and https://bugzilla.mozilla.org/show_bug.cgi?id=965003#c7
As far as I understand PDF.js used the 'PlayPreview' feature (Playpreview is the overlay you get to see to confirm you want to activate a plugin) as a 'hack' to inject PDF.js HTML content (resource://pdf.js/web/viewer.html) into the page because the plugin architecture was not flexible enough. So, even though technically PlayPreview is not part of PDF.js, the combination of PDF.js and PlayPreview specifically made it possible to inject content into PlayPreview and bypass the CSP.