hwp
Warn
Audited by Snyk on Aug 15, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The required workflow reads outsider-authored free text at runtime when an external user supplies an HWP/HWPX file whose internal sections/
hp:telements are parsed and converted to Markdown (e.g.,hwp-parser.worker.tsreceives{type:'parse', data:fileBuffer}and extracts text fromBodyText/Section0orContents/section*.xml).
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata