THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-3753-m2x2-q623 (high) — File Viewer: DOM XSS via unsafe hyperlink schemes in the legacy DOC renderer

[GHSA] GHSA-3753-m2x2-q623 (high) — File Viewer: DOM XSS via unsafe hyperlink schemes in the legacy DOC renderer

medgithub_advisoriesPublished 2026-09-18

GHSA-3753-m2x2-q623 Severity: high CVE: CVE-2026-91127

File Viewer: DOM XSS via unsafe hyperlink schemes in the legacy DOC renderer

### Summary

Before 2.3.1, the legacy `.doc` renderer emitted document hyperlink targets after HTML escaping but without a URL-scheme allowlist. A crafted `.doc` could therefore render a live `javascript:`, `vbscript:`, `data:`, or similarly unsafe link. Script coul

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-3753-m2x2-q623