First published: Thu Feb 20 2025(Updated: )
### Impact During a recent internal audit, we identified a Cross-Site Scripting (XSS) vulnerability in the CKEditor 5 real-time collaboration package. This vulnerability can lead to unauthorized JavaScript code execution and affects user markers, which represent users' positions within the document. This vulnerability affects only installations with [Real-time collaborative editing](https://ckeditor.com/docs/ckeditor5/latest/features/collaboration/real-time-collaboration/real-time-collaboration.html) enabled. ### Patches The problem has been recognized and patched. The fix will be available in version 44.2.1 (and above). ### For more information Email us at [security@cksource.com](mailto:security@cksource.com) if you have any questions or comments about this advisory.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
CKEditor 5 | <44.2.1 | |
npm/ckeditor5-premium-features | >=42.0.0<44.2.0 | 44.2.1 |
npm/@ckeditor/ckeditor5-real-time-collaboration | >=41.3.0<=44.2.0 | 44.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-25299 is classified as a high-severity Cross-Site Scripting (XSS) vulnerability in CKEditor 5.
To fix CVE-2025-25299, update CKEditor 5 to version 44.2.1 or later.
CVE-2025-25299 affects versions of CKEditor 5 prior to 44.2.1.
CVE-2025-25299 can allow an attacker to execute arbitrary JavaScript in the context of the affected user's session.
Yes, CVE-2025-25299 specifically affects the real-time collaboration package in CKEditor 5.