PT-2026-95555 · Npm · Msdoc-Viewer+1
CVE-2026-91127
·
Published
2026-09-18
·
Updated
2026-09-26
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
@file-viewer/doc versions prior to 2.3.1
msdoc-viewer versions prior to 0.2.2
Description
The legacy DOC renderer fails to restrict URL schemes when emitting document-controlled hyperlink targets into generated HTML. A crafted legacy DOC file can include unsafe schemes such as
javascript:, vbscript:, or data: in a rendered link. If a user clicks the link, arbitrary script can execute within the origin of the embedding application.Recommendations
Update @file-viewer/doc to version 2.3.1.
Update msdoc-viewer to version 0.2.2.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
@File-Viewer/Doc
Msdoc-Viewer