Impact
The vulnerability stems from the rhwp browser extensions having unfettered host permissions that allow them to perform network requests to any URL. The service workers handling fetches for preview files and thumbnails do not validate the sender, URL scheme, or destination before executing the privileged fetch. As a result, an untrusted webpage can instruct the extension to retrieve resources from localhost or other private network nodes. If the requested HWP/HWPX file includes an extractable preview image, the extension returns that preview as a data URI embedded in the page’s DOM, making the image data readable by the page’s script. In addition, the ability to request arbitrary internal URLs can reveal the existence of internal resources, perform port scans, and help an attacker fingerprint the presence and version of the extension. No direct code execution is possible; the flaw enables information leakage and reconnaissance.
Affected Systems
The affected product is the rhwp HWP viewer and editor maintained by edwardkim. Prior to version 0.7.15 for the standalone application and Chrome/Firefox extensions 0.2.4, these extensions granted a wildcard host permission and exposed a service worker that prematurely fetched URLs. Any user who has these older versions installed and visits an untrusted page while the extension is active is at risk. The fix is implemented in rhwp 0.7.15 and the extension 0.2.4 for both Chrome and Firefox.
Risk and Exploitability
The CVSS score of 4.7 indicates a medium severity vulnerability. The EPSS score of less than 1% suggests that exploitation is unlikely, especially since it requires a user to intentionally visit an untrusted page and the extension must be enabled. The vulnerability is not listed in the CISA KEV catalog, further reducing its threat profile. Exploitation is possible via a standard SSRF attack vector, with the attacker leveraging client‑side scripts on a malicious site to send carefully crafted messages to the extension’s service worker. Because the flaw does not grant arbitrary code execution, the impact remains limited to leakage of preview data, existence checking, port probing, and a minimal fingerprinting capability.
OpenCVE Enrichment