PT-2026-95093 · Mozilla Firefox+2 · Rhwp Firefox Extension+2
CVSS v3.1
4.7
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
rhwp versions prior to 0.7.15
rhwp Chrome and Firefox extension versions prior to 0.2.4
Description
Service workers in the browser extensions do not validate message senders, URL schemes, or destination addresses before performing privileged fetches. This allows an untrusted page to trigger the
fetch-file and extract-thumbnail handlers to request resources from localhost or private networks. If a target HWP or HWPX file contains an extractable PrvImage, the extension returns the preview as a data URI in the page-readable DOM, enabling page scripts to read it. Additionally, this flaw allows for port probing, internal-resource existence checks, and fingerprinting of the extension's presence or version. Exploitation occurs when a user visits an untrusted page while the extension is enabled.Recommendations
Update rhwp to version 0.7.15.
Update rhwp Chrome and Firefox extension to version 0.2.4.
Exploit
Fix
SSRF
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rhwp
Rhwp Chrome Extension
Rhwp Firefox Extension