Description
rhwp is an HWP viewer and editor implemented in Rust and WebAssembly. Prior to rhwp 0.7.15 and rhwp Chrome and Firefox extension 0.2.4, the browser extensions use an all-URLs host permission to detect HWP and HWPX links on visited pages, but the service workers do not validate message senders, URL schemes, or destination addresses before privileged fetches. The affected paths are rhwp-chrome/manifest.json, rhwp-chrome/content-script.js, rhwp-chrome/sw/message-router.js, rhwp-chrome/sw/thumbnail-extractor.js, rhwp-firefox/manifest.json, rhwp-firefox/content-script.js, rhwp-firefox/sw/message-router.js, and rhwp-firefox/sw/thumbnail-extractor.js. An untrusted page can make the fetch-file and extract-thumbnail handlers request localhost or private-network resources. When a target HWP or HWPX file contains an extractable PrvImage, the extension returns the preview as a data URI in page-readable DOM, allowing page script to read it. The flaw also permits internal-resource existence and port probing and extension presence or version fingerprinting. Exploitation requires a user to visit an untrusted page while the extension is enabled, and preview disclosure is limited to an extractable PrvImage. This issue is fixed in rhwp 0.7.15 and rhwp Chrome and Firefox extension 0.2.4.
Published: 2026-09-17
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information disclosure of internal preview data and internal network probing
Action: Apply Patch
AI Analysis

Impact

The vulnerability stems from the rhwp browser extensions having unfettered host permissions that allow them to perform network requests to any URL. The service workers handling fetches for preview files and thumbnails do not validate the sender, URL scheme, or destination before executing the privileged fetch. As a result, an untrusted webpage can instruct the extension to retrieve resources from localhost or other private network nodes. If the requested HWP/HWPX file includes an extractable preview image, the extension returns that preview as a data URI embedded in the page’s DOM, making the image data readable by the page’s script. In addition, the ability to request arbitrary internal URLs can reveal the existence of internal resources, perform port scans, and help an attacker fingerprint the presence and version of the extension. No direct code execution is possible; the flaw enables information leakage and reconnaissance.

Affected Systems

The affected product is the rhwp HWP viewer and editor maintained by edwardkim. Prior to version 0.7.15 for the standalone application and Chrome/Firefox extensions 0.2.4, these extensions granted a wildcard host permission and exposed a service worker that prematurely fetched URLs. Any user who has these older versions installed and visits an untrusted page while the extension is active is at risk. The fix is implemented in rhwp 0.7.15 and the extension 0.2.4 for both Chrome and Firefox.

Risk and Exploitability

The CVSS score of 4.7 indicates a medium severity vulnerability. The EPSS score of less than 1% suggests that exploitation is unlikely, especially since it requires a user to intentionally visit an untrusted page and the extension must be enabled. The vulnerability is not listed in the CISA KEV catalog, further reducing its threat profile. Exploitation is possible via a standard SSRF attack vector, with the attacker leveraging client‑side scripts on a malicious site to send carefully crafted messages to the extension’s service worker. Because the flaw does not grant arbitrary code execution, the impact remains limited to leakage of preview data, existence checking, port probing, and a minimal fingerprinting capability.

Generated by OpenCVE AI on September 19, 2026 at 02:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update rhwp to version 0.7.15 or later and upgrade Chrome and Firefox extensions to 0.2.4 or newer to restore validated URL checks.
  • If an upgrade is not immediately possible, disable or uninstall the rhwp extension to prevent privileged network requests from being performed.
  • Implement a browser or system level network filter that blocks internal or private network requests from web extensions, providing a temporary safeguard against SSRF exploitation.

Generated by OpenCVE AI on September 19, 2026 at 02:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Edwardkim
Edwardkim rhwp
Vendors & Products Edwardkim
Edwardkim rhwp

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description rhwp is an HWP viewer and editor implemented in Rust and WebAssembly. Prior to rhwp 0.7.15 and rhwp Chrome and Firefox extension 0.2.4, the browser extensions use an all-URLs host permission to detect HWP and HWPX links on visited pages, but the service workers do not validate message senders, URL schemes, or destination addresses before privileged fetches. The affected paths are rhwp-chrome/manifest.json, rhwp-chrome/content-script.js, rhwp-chrome/sw/message-router.js, rhwp-chrome/sw/thumbnail-extractor.js, rhwp-firefox/manifest.json, rhwp-firefox/content-script.js, rhwp-firefox/sw/message-router.js, and rhwp-firefox/sw/thumbnail-extractor.js. An untrusted page can make the fetch-file and extract-thumbnail handlers request localhost or private-network resources. When a target HWP or HWPX file contains an extractable PrvImage, the extension returns the preview as a data URI in page-readable DOM, allowing page script to read it. The flaw also permits internal-resource existence and port probing and extension presence or version fingerprinting. Exploitation requires a user to visit an untrusted page while the extension is enabled, and preview disclosure is limited to an extractable PrvImage. This issue is fixed in rhwp 0.7.15 and rhwp Chrome and Firefox extension 0.2.4.
Title rhwp browser extension performs SSRF / private-network requests and leaks HWP preview data to untrusted pages
Weaknesses CWE-1385
CWE-200
CWE-359
CWE-918
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-21T21:13:40.752Z

Reserved: 2026-06-15T19:15:27.342Z

Link: CVE-2026-54565

cve-icon Vulnrichment

Updated: 2026-09-21T21:13:35.089Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T21:17:16.543

Modified: 2026-09-24T21:25:27.050

Link: CVE-2026-54565

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T02:30:17Z

Weaknesses
  • CWE-1385

    Missing Origin Validation in WebSockets

  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-359

    Exposure of Private Personal Information to an Unauthorized Actor

  • CWE-918

    Server-Side Request Forgery (SSRF)