GHSA-3753-m2x2-q623
HIGHCVE-2026-91127Before 2.3.1, the legacy .doc renderer emitted document hyperlink targets after HTML escaping but without a URL-scheme allowlist. A crafted .doc could therefore render a live javascript:, vbscript:, data:, or similarly unsafe link. Script could execute in the embedding origin if a viewer clicked it.
- Affected
- <= 2.3.0
- Fixed in
- 2.3.1
- Weakness
- CWE-79
- Published
- 2026-09-18
- Source
- github