PT-2026-95998 · Npm · @Eigenpal/Docx-Editor-Core+1
Published
2026-09-10
·
Updated
2026-09-10
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N |
Summary
Embedded font-family names (
word/fontTable.xml) were interpolated unescaped into an injected @font-face <style> and into the print window's document.write(). A crafted name injects page-wide CSS on open, and breaks out of <style>
into executable HTML on Print.Impact
Opening a crafted
.docx applies attacker-controlled CSS page-wide with zero clicks (overlay/phishing, attribute-selector exfiltration of input values, tracking beacons). Clicking Print escalates to script execution in the embedder's origin.Remediation
Upgrade to 1.8.3. Font names are CSS-escaped before interpolation (quotes, backslash,
< >, and CSS newlines), and the print window is assembled with DOM APIs instead of document.write.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
@Eigenpal/Docx-Editor-Core
@Eigenpal/Docx-Editor-React