GHSA-x7m8-jrm8-hpvx: @eigenpal/docx-editor-react: CSS injection and print-time XSS via unescaped embedded font-family name
Embedded font-family names (word/fontTable.xml) were interpolated unescaped into an injected @font-face <style> and into the print window’s document.write(). A crafted name injects page-wide CSS on open, and breaks out of <style>
into executable HTML on Print.
References
Code Behaviors & Features
Detect and mitigate GHSA-x7m8-jrm8-hpvx with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →