Stored XSS via link with Word file leads to leaks JWT token
Description
From Bugcrowd:
I found an stored XSS vulnerability via Word file when embed the link. As an attacker, I can enter a phishing/malware website or take JWT auth. If successful, a XSS attack can severely impact websites and web applications, damage reputation and relationships with customers. XSS can deface websites, can result in compromised user accounts, and can run malicious code on web pages, which can lead to a compromise of the user’s device.
Steps to reproduce:
-
Create a Macro with Word as Input and Attachment as Source
-
Select the .docx file containing XSS injection as attachment:
xss.docxPreview unavailable11.4 KiB -
Save the macro and publish the page
-
Click on the link in the macro
Activity
Show
Released
Add watchers
Details
Priority
Created
15 June 2026, 15:18
Updated
17 June 2026, 20:05
Created: 15 June 2026, 13:18
Updated: 17 June 2026, 18:05
Confirmed fixed in QA env.