AIKIDO-2024-10556

@tiptap/extension-link is vulnerable to Cross-site Scripting (XSS)

46

Medium

@tiptap/extension-link JS

AIKIDO-2024-10556: @tiptap/extension-link is vulnerable to Cross-site Scripting (XSS) in versions 2.0.0 - 2.10.3.

Cross-site Scripting (XSS)
Vuln in 2.0.0 - 2.10.3
Fixed in 2.10.4
No CVE available
TL;DR

Who does this affect?

How can it be fixed?

Background info

Link to vendor website

Logo
ยฉ 2024 Aikido Security BV | BE0792914919
๐Ÿ‡ช๐Ÿ‡บ Registered address: Coupure Rechts 88, 9000, Ghent, Belgium
๐Ÿ‡ช๐Ÿ‡บ Office address: Gebroeders van Eyckstraat 2, 9000, Ghent, Belgium
๐Ÿ‡บ๐Ÿ‡ธ Office address: 95 Third St, 2nd Fl, San Francisco, CA 94103, US
Any use of the intel.aikido.dev website and content is explicitly subject to Aikido Terms of Use