THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-x7m8-jrm8-hpvx (high) — @eigenpal/docx-editor-react: CSS injection and print-time XSS via unescaped embedded font-family name

[GHSA] GHSA-x7m8-jrm8-hpvx (high) — @eigenpal/docx-editor-react: CSS injection and print-time XSS via unescaped embedded font-family name

medgithub_advisoriesPublished 2026-09-10

GHSA-x7m8-jrm8-hpvx Severity: high CVE: None

@eigenpal/docx-editor-react: CSS injection and print-time XSS via unescaped embedded font-family name

## Summary Embedded font-family names (`word/fontTable.xml`) were interpolated unescaped into an injected `@font-face` `<style>` and into the print window's `document.write()`. A crafted name injects page-wide CSS on open, and breaks out of `<style>`

Original source: https://github.com/advisories/GHSA-x7m8-jrm8-hpvx