Intel

AIKIDO-2024-10182

prosemirror-model is vulnerable to Cross-site Scripting (XSS)

Cross-site Scripting (XSS) Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jul 15, 2024

15

Low Risk

This Affects:

JSprosemirror-model
1.0.0 - 1.22.0
Fixed in 1.22.1
Are you affected? Scan for Free

TL;DR

Affected versions of the package are vulnerable to Cross-site Scripting (XSS). The patched version adds code to DOMSerializer that rejects DOM output specs originating from attribute values, protecting against XSS attacks that exploit corrupt attribute input.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

prosemirror-model is vulnerable to Cross-site Scripting (XSS) in versions 1.0.0 - 1.22.0.

How to fix this

Upgrade the prosemirror-model library to the patch version.