PT-2026-95093 · Mozilla Firefox+2 · Rhwp Firefox Extension+2

·

CVE-2026-54565

·

Published

2026-09-17

·

Updated

2026-09-21

CVSS v3.1

4.7

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions rhwp versions prior to 0.7.15 rhwp Chrome and Firefox extension versions prior to 0.2.4
Description Service workers in the browser extensions do not validate message senders, URL schemes, or destination addresses before performing privileged fetches. This allows an untrusted page to trigger the fetch-file and extract-thumbnail handlers to request resources from localhost or private networks. If a target HWP or HWPX file contains an extractable PrvImage, the extension returns the preview as a data URI in the page-readable DOM, enabling page scripts to read it. Additionally, this flaw allows for port probing, internal-resource existence checks, and fingerprinting of the extension's presence or version. Exploitation occurs when a user visits an untrusted page while the extension is enabled.
Recommendations Update rhwp to version 0.7.15. Update rhwp Chrome and Firefox extension to version 0.2.4.

Exploit

Fix

SSRF

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54565
GHSA-J972-M9FH-G22M

Affected Products

Rhwp
Rhwp Chrome Extension
Rhwp Firefox Extension