CVE-2026-91127: File Viewer: DOM XSS via unsafe hyperlink schemes in the legacy DOC renderer
Before 2.3.1, the legacy .doc renderer emitted document hyperlink targets after HTML escaping but without a URL-scheme allowlist. A crafted .doc could therefore render a live javascript:, vbscript:, data:, or similarly unsafe link. Script could execute in the embedding origin if a viewer clicked it.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-91127 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →