Junglewise Threat Intelligence

CVE-2026-30691: Cyntler react-doc-viewer XSS in TXTRenderer

CVE-2026-30691 · Severity: medium · CVSS 6.1 · Published 2026-05-20

Vendors: npm.

Executive brief

A vulnerability exists in a popular React document viewing library used to display various file types in web applications. If a user views a specially crafted text file through this component, an attacker can execute malicious code in the user's browser. This could lead to the theft of login session information, unauthorized actions on the user's behalf, or the display of fraudulent content.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in @cyntler/react-doc-viewer versions up to and including 1.17.1. The root cause is located in the TXTRenderer component (src/renderers/txt/index.tsx), where raw file data from .txt files is explicitly cast as a ReactNode without sanitization. An attacker can exploit this by providing a crafted text file containing malicious HTML or JavaScript. When a victim views the file, the script executes within their browser context. As of the advisory date, no official patch is available; developers are advised to manually sanitize input using libraries like DOMPurify or avoid unsafe casting.

Affected products

  • cyntler @cyntler/react-doc-viewer <= 1.17.1

Timeline

  • 2026-02-13: disclosed: Vulnerability reported on GitHub issues
  • 2026-05-20: advisory: GitHub Advisory and CVE published

References