Intel

AIKIDO-2025-10108

@ckeditor/ckeditor5-real-time-collaboration is vulnerable to Cross-site Scripting

Cross-site ScriptingCVE-2025-25299 Published Feb 22, 2025

75

High Risk

This Affects:

JS@ckeditor/ckeditor5-real-time-collaboration
41.3.0 - 44.2.0
Fixed in 44.2.1
Are you affected? Scan for Free

TL;DR

A Cross-Site Scripting (XSS) vulnerability has been disclosed in the @ckeditor/ckeditor5-real-time-collaboration package. This vulnerability allows unauthorized execution of JavaScript by manipulating user markers, which track users' positions within a document. It affects environments where Real-Time Collaborative Editing is enabled. If exploited, this issue could lead to malicious script execution within users' sessions.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@ckeditor/ckeditor5-real-time-collaboration is vulnerable to Cross-site Scripting in versions 41.3.0 - 44.2.0.

How to fix this

Upgrade the @ckeditor/ckeditor5-real-time-collaboration library to the patch version.