PT-2026-95555 · Npm · Msdoc-Viewer+1

CVE-2026-91127

·

Published

2026-09-18

·

Updated

2026-09-26

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions @file-viewer/doc versions prior to 2.3.1 msdoc-viewer versions prior to 0.2.2
Description The legacy DOC renderer fails to restrict URL schemes when emitting document-controlled hyperlink targets into generated HTML. A crafted legacy DOC file can include unsafe schemes such as javascript:, vbscript:, or data: in a rendered link. If a user clicks the link, arbitrary script can execute within the origin of the embedding application.
Recommendations Update @file-viewer/doc to version 2.3.1. Update msdoc-viewer to version 0.2.2.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-91127
GHSA-3753-M2X2-Q623

Affected Products

@File-Viewer/Doc
Msdoc-Viewer