PT-2026-95998 · Npm · @Eigenpal/Docx-Editor-Core+1
Publicado
2026-09-10
·
Atualizado
2026-09-10
CVSS v3.1
8.1
Alta
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N |
Summary
Embedded font-family names (
word/fontTable.xml) were interpolated unescaped into an injected @font-face <style> and into the print window's document.write(). A crafted name injects page-wide CSS on open, and breaks out of <style>
into executable HTML on Print.Impact
Opening a crafted
.docx applies attacker-controlled CSS page-wide with zero clicks (overlay/phishing, attribute-selector exfiltration of input values, tracking beacons). Clicking Print escalates to script execution in the embedder's origin.Remediation
Upgrade to 1.8.3. Font names are CSS-escaped before interpolation (quotes, backslash,
< >, and CSS newlines), and the print window is assembled with DOM APIs instead of document.write.Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
@Eigenpal/Docx-Editor-Core
@Eigenpal/Docx-Editor-React