Medium · 5.1 Node.js & npm GHSA-3753-m2x2-q623 CVE-2026-91127
DOM XSS in File Viewer's Legacy DOC Renderer via Unsafe Hyperlink Schemes (CVE-2026-91127)
File Viewer's legacy DOC renderer failed to restrict URL schemes in document-controlled hyperlinks, allowing a crafted DOC file to trigger script execution in the embedding application's origin when a user clicks the link. Fixed in @file-viewer/doc 2.3.1 and msdoc-viewer 0.2.2.
AI summary
A cross-site scripting vulnerability has been disclosed in File Viewer, a browser-native viewer used to render Office, PDF, CAD, archive, and other file types inside private and internal web applications. The issue affects the legacy DOC renderer component and is tracked as CVE-2026-91127 (GHSA-3753-m2x2-q623). It has been assigned a PatchBriefing score of 5.1, based primarily on a CVSS base score of 8.2. Fixed versions are available for both affected packages.
What happened
File Viewer's legacy DOC renderer takes hyperlink targets embedded in a DOC document and writes them into the HTML it generates for display. Prior to the fix, the renderer applied character escaping to these document-controlled hyperlink targets but did not restrict which URL schemes were allowed. As a result, a specially crafted legacy DOC file could place a scheme such as javascript:, vbscript:, data:, or another unsafe scheme into a rendered link. If a user then clicked that link, script could execute within the origin of the application embedding File Viewer.
Technical cause
The root cause is improper neutralization of input during web page generation, classified as CWE-79 (Cross-site Scripting). Escaping characters in the hyperlink text does not prevent execution if the underlying URL scheme itself is left unrestricted, since schemes like javascript: or vbscript: trigger code execution independent of character escaping in the visible link text.
Why it matters
Because File Viewer is embedded in private and internal web applications to render untrusted or semi-trusted files, a malicious DOC file delivered through normal workflows (e.g., document upload or sharing) could lead to script execution in the context of the hosting application once a user clicks a rendered link. The CVSS vector indicates the attack is network-based, requires low attack complexity, needs no privileges, but does require user interaction (clicking the link), and impacts confidentiality (high) and integrity (low) within a changed scope.
Who is affected
Applications that embed the @file-viewer/doc package at version 2.3.0 or earlier, or the msdoc-viewer package at version 0.2.1 or earlier, to render legacy DOC files are affected.
Affected versions
@file-viewer/doc: versions up to and including 2.3.0 are affected; fixed in 2.3.1. msdoc-viewer: versions up to and including 0.2.1 are affected; fixed in 0.2.2.
Fixes and mitigation
The fix blocks external document-controlled links by default. When external links are explicitly enabled by the embedding application, only HTTP(S), mail, telephone, safe relative URLs, and internal bookmarks are permitted. Mount-boundary sanitization is also applied as an additional defense-in-depth measure. These changes are included in @file-viewer/doc 2.3.1 and msdoc-viewer 0.2.2.
Recommended action
Update @file-viewer/doc to version 2.3.1 or later, and msdoc-viewer to version 0.2.2 or later. Review any application configuration that explicitly enables external links in rendered documents to confirm it relies on the updated scheme restrictions rather than custom handling.
PatchBriefing score
5.1 / 10 · Medium
Official CVSS: 8.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Why this score
The PatchBriefing score of 5.1 reflects a CVSS base score of 8.2, which contributes the bulk of the score (4.51 points). An additional 0.6 points are added because the vulnerability is reachable over the network without authentication. No points are contributed by known exploitation, public exploit availability, or EPSS, as there is no evidence of active exploitation or a public exploit, and the EPSS probability is low (0.397%, 31.53th percentile). The vulnerability does require user interaction (clicking a malicious link), which is reflected in the CVSS vector and limits the score compared to vulnerabilities requiring no interaction. A fix is available for both affected packages, which also keeps the no_fix_available contribution at zero.
Affected versions
- @file-viewer/doc <= 2.3.0
- vulnerable
- ≥ 2.3.1
- patched
- msdoc-viewer <= 0.2.1
- vulnerable
- ≥ 0.2.2
- patched
Reported fixes
The fix blocks external document-controlled links by default. When external links are explicitly enabled by the embedding application, only HTTP(S), mail, telephone, safe relative URLs, and internal bookmarks are permitted. Mount-boundary sanitization is also applied as an additional defense-in-depth measure. These changes are included in @file-viewer/doc 2.3.1 and msdoc-viewer 0.2.2.
How this was built
2 source records were collected, matched and used to prepare the report above.
-
GitHub Advisory Database database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email