Security Vulnerability in HWP Viewer and Editor by Rhwp
CVE-2026-54565

4.7MEDIUM

Key Information:

Vendor

Edwardkim

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-54565?

Rhwp, an HWP viewer and editor, has a security flaw in its Chrome and Firefox extensions, where it utilizes all-URLs host permission without proper validation of message senders, URL schemes, or destination addresses. This oversight allows an untrusted page to exploit the extension's fetch capabilities, potentially retrieving sensitive resources from localhost or private networks. The issue arises particularly when handling HWP or HWPX files with extractable PrvImages, which can be improperly exposed as data URIs in the webpage's DOM. This flaw could lead to resource existence probing and fingerprinting of the extension's version without user awareness. Users are encouraged to update to rhwp 0.7.15 and relevant browser extensions versions to mitigate risks.

Affected Version(s)

rhwp < 0.7.15

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.