Intel

AIKIDO-2025-10308

froala-editor is vulnerable to Dependency on Vulnerable Third-Party Component

Dependency on Vulnerable Third-Party Component Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published May 14, 2025

10

Low Risk

This Affects:

JSfroala-editor
2.0.2 - 4.5.1
Fixed in 4.5.2
Are you affected? Scan for Free

TL;DR

Affected versions of this package import a deprecated and vulnerable Content Delivery Network (CDN) files, which may expose the application to ReDoS (Regular Expression Denial of Service). Additionally, more fixes were applied directly to minified JS files, making these changes untraceable.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

froala-editor is vulnerable to Dependency on Vulnerable Third-Party Component in versions 2.0.2 - 4.5.1.

How to fix this

Upgrade the froala-editor library to a patch version.