Impact
The legacy DOC renderer in File Viewer emits hyperlink targets into the generated HTML after escaping content, but does not restrict the URL scheme. A maliciously crafted legacy DOC file can include schemes such as javascript:, vbscript:, data:, or other unsafe schemes in a link. When a user clicks that link, the script runs in the context of the host web application, allowing arbitrary JavaScript execution within the embedding application's origin.
Affected Systems
Affected vendors include @file-viewer and flyfish‑dev with the products @file-viewer/doc, flyfish‑dev:file‑viewer, and flyfish‑dev:msdoc‑viewer. All versions prior to @file-viewer/doc 2.3.1 and msdoc‑viewer 0.2.2 are vulnerable. Updates as indicated in the referenced releases and security advisory resolve the issue.
Risk and Exploitability
The CVSS score of 8.2 indicates high severity. The EPSS score is below 1 %, indicating a low probability of exploitation in the wild at present. The issue is not listed in the CISA KEV catalog. The likely attack vector involves an application that loads legacy DOC files; a crafted document can be supplied by an attacker, and the victim must click an unsafe link for the script to run. Once executed, the attacker can run arbitrary JavaScript within the hosting web application’s client side.
OpenCVE Enrichment
Github GHSA