OCTOBER 11, 2026
Live Feed
Back to database
Case File

CVE-2026-91127

HIGH · CVSS 8.2 EPSS 0.40% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-18 · Last synced 2026-10-11

CyberRota Analysis

AI-Generated

The vulnerability affects the File Viewer component in Office and Java applications, allowing crafted legacy DOC files to generate unsafe hyperlink targets that could execute scripts in the embedding application's origin. This poses a significant risk of cross-site scripting (XSS) attacks when users interact with malicious links. Organizations using affected versions should prioritize applying the updates to @file-viewer/doc 2.3.1 and msdoc-viewer 0.2.2 to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-91127
Severity
HIGH
CVSS
8.2
EPSS
0.40%
Office Java

Original NVD Description

File Viewer is a browser-native viewer for Office, PDF, CAD, archive, and other files in private and internal web applications. Prior to @file-viewer/doc 2.3.1 and msdoc-viewer 0.2.2, the legacy DOC renderer emitted document-controlled hyperlink targets into generated HTML after character escaping but without restricting URL schemes. A crafted legacy DOC file could place javascript:, vbscript:, data:, or another unsafe scheme in a rendered link, and script could execute in the embedding application's origin when a user clicked the link. The fix blocks external document links by default, allows only HTTP(S), mail, telephone, safe relative URLs, and internal bookmarks when external links are explicitly enabled, and applies mount-boundary sanitization as defense in depth. This issue is fixed in @file-viewer/doc 2.3.1 and msdoc-viewer 0.2.2.