Security Vulnerability in HWP Viewer and Editor by Rhwp
CVE-2026-54565
What is CVE-2026-54565?
Rhwp, an HWP viewer and editor, has a security flaw in its Chrome and Firefox extensions, where it utilizes all-URLs host permission without proper validation of message senders, URL schemes, or destination addresses. This oversight allows an untrusted page to exploit the extension's fetch capabilities, potentially retrieving sensitive resources from localhost or private networks. The issue arises particularly when handling HWP or HWPX files with extractable PrvImages, which can be improperly exposed as data URIs in the webpage's DOM. This flaw could lead to resource existence probing and fingerprinting of the extension's version without user awareness. Users are encouraged to update to rhwp 0.7.15 and relevant browser extensions versions to mitigate risks.
Affected Version(s)
rhwp < 0.7.15
