GHSA-c8x8-7fp4-3x9w: XSS
Impact
When a user pastes attacker-provided HTML into a ProseMirror editor component, this can cause attacker-controlled JavaScript code to run in the browser window containing the editor.
Patches
Version 1.42.3 adds validation that prevents this attack.
Workarounds
No known workarounds.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/prosemirror-viewto a version that resolves this vulnerability.Fixed in 1.42.3 - Upgrade
Upgrade
ProseMirrorto a version that resolves this vulnerability.Fixed in 1.42.3
Event History
Frequently Asked Questions
Who is exposed to this issue?
Applications using npm/prosemirror-view are exposed when users can paste attacker-provided HTML into a ProseMirror editor component. The impact is execution of attacker-controlled JavaScript in the browser window containing that editor.
What must an attacker be able to do to exploit it?
The attacker must cause a user to paste attacker-provided HTML into the ProseMirror editor component. The provided information does not describe exploitation through other input paths.
Which version fixes the issue?
Version 1.42.3 adds validation intended to prevent this attack.
What can be done if updating is not immediately possible?
No known workaround is available. Prioritize updating and, until then, avoid allowing users to paste untrusted HTML into affected editor components.