Skip to content
archivevulnerability · 10 Sep 2026 · 15:06 UTC

GHSA-x7m8-jrm8-hpvx: @eigenpal/docx-editor-react: CSS injection and print-time XSS via unescaped embedded font-family name

HIGHHigh-risk vulnerability — CVSS 8.1

last 60 dispatches · spectrum

## Summary Embedded font-family names (`word/fontTable.xml`) were interpolated unescaped into an injected `@font-face` ` ` and into the print window's `document.write()`. A crafted name injects page-wide CSS on open, and breaks out of ` ` into executable HTML on Print. ## Impact Opening a crafted `.docx` applies attacker-controlled CSS page-wide with zero clicks (overlay/phishing, attribute-selector exfiltration of input values, tracking beacons). Clicking Print escalates to script execution in the embedder's origin. ## Remediation Upgrade to 1.8.3. …

grounded ✓primary source ↗

loading threat intel…

Early access

Get the next one first.

Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.

bot-protected