Medium · 5.1 Node.js & npm GHSA-x7m8-jrm8-hpvx
CSS Injection and Print-Time XSS in @eigenpal/docx-editor-react via Unescaped Font Names
A vulnerability in @eigenpal/docx-editor-react and @eigenpal/docx-editor-core allows a crafted .docx file to inject page-wide CSS on open and execute script when the document is printed, due to unescaped embedded font names. Fixed in version 1.8.3.
AI summary
A vulnerability has been published for @eigenpal/docx-editor-react and its companion package @eigenpal/docx-editor-core, two components used to render Word documents in the browser. The issue, tracked as GHSA-x7m8-jrm8-hpvx, stems from how embedded font names in .docx files are handled when generating CSS and print output. The vendor has released a fix in version 1.8.3.
What Happened
A security advisory (GHSA-x7m8-jrm8-hpvx) describes a CSS injection and cross-site scripting (XSS) vulnerability in @eigenpal/docx-editor-react and @eigenpal/docx-editor-core. The vulnerability involves embedded font-family names read from a document's font table being interpolated into generated CSS and into the HTML used for a print preview window without proper escaping.
Technical Cause
According to the advisory, font-family names embedded in the `word/fontTable.xml` portion of a .docx file were inserted, unescaped, into a dynamically injected `@font-face` `<style>` block and into a print window built using `document.write()`. A crafted font name can therefore inject arbitrary CSS when the document is opened, and can break out of the `<style>` context into executable HTML when the Print function is used. This corresponds to CWE-79, Improper Neutralization of Input During Web Page Generation (Cross-site Scripting).
Why It Matters
Per the advisory, simply opening a crafted .docx file applies attacker-controlled CSS across the page with no further interaction required. This can be used for overlay or phishing attacks, or to exfiltrate values from input fields using CSS attribute selectors, as well as to plant tracking beacons. If a user then clicks Print, the vulnerability escalates to script execution within the embedding application's origin, which could allow further compromise of the page or session depending on what that origin has access to.
Who Is Affected
Any application that embeds @eigenpal/docx-editor-react or depends on @eigenpal/docx-editor-core to render .docx files, and that allows users to open documents from untrusted or external sources, is potentially affected.
Affected Versions
Both @eigenpal/docx-editor-react and @eigenpal/docx-editor-core are affected in versions from 0 up to and including 1.8.2. The vendor has fixed the issue in version 1.8.3 for both packages.
Fixes and Mitigation
The advisory states that version 1.8.3 resolves the issue by CSS-escaping font names before they are interpolated into generated styles (handling quotes, backslashes, angle brackets, and CSS newlines), and by building the print window using DOM APIs instead of `document.write()`.
Recommended Action
Upgrade @eigenpal/docx-editor-react and @eigenpal/docx-editor-core to version 1.8.3 as soon as practical, particularly for any deployment that opens .docx files from untrusted sources. Review application logs or document-handling workflows if there is reason to believe crafted documents may have been opened prior to patching; the fact package does not include guidance on detection, so no further detection steps can be confirmed here.
PatchBriefing score
5.1 / 10 · Medium
Official CVSS: 8.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Why this score
This issue has a CVSS base score of 8.1 (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N), reflecting a network-exploitable vulnerability requiring no privileges but some user interaction (opening a document, and for the XSS escalation, clicking Print), with high impact to confidentiality and integrity and no impact to availability. The computed PatchBriefing score of 5.1 factors in the CVSS base score as the primary driver, a small addition for the vulnerability being exploitable without authentication, and no additional weight from known exploitation, public exploit code, or EPSS data, none of which were reported for this advisory. A fix is available, which also limits the score relative to unpatched issues.
Affected versions
- @eigenpal/docx-editor-react <= 1.8.2
- vulnerable
- ≥ 1.8.3
- patched
- @eigenpal/docx-editor-core <= 1.8.2
- vulnerable
- ≥ 1.8.3
- patched
Reported fixes
The advisory states that version 1.8.3 resolves the issue by CSS-escaping font names before they are interpolated into generated styles (handling quotes, backslashes, angle brackets, and CSS newlines), and by building the print window using DOM APIs instead of `document.write()`.
How this was built
1 source records were collected, matched and used to prepare the report above.
-
GitHub Advisory Database database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email