THREAT OPS › Threat News › [GHSA] GHSA-3753-m2x2-q623 (high) — File Viewer: DOM XSS via unsafe hyperlink schemes in the legacy DOC renderer
[GHSA] GHSA-3753-m2x2-q623 (high) — File Viewer: DOM XSS via unsafe hyperlink schemes in the legacy DOC renderer
GHSA-3753-m2x2-q623 Severity: high CVE: CVE-2026-91127
File Viewer: DOM XSS via unsafe hyperlink schemes in the legacy DOC renderer
### Summary
Before 2.3.1, the legacy `.doc` renderer emitted document hyperlink targets after HTML escaping but without a URL-scheme allowlist. A crafted `.doc` could therefore render a live `javascript:`, `vbscript:`, `data:`, or similarly unsafe link. Script coul
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- CVE-2026-91127cve
Original source: https://github.com/advisories/GHSA-3753-m2x2-q623