Intel

AIKIDO-2025-10380

wikimedia/parsoid is vulnerable to Cross-site Scripting (XSS)

Cross-site Scripting (XSS)CVE-2025-32699 Published Jun 17, 2025

21

Low Risk

This Affects:

PHPwikimedia/parsoid
0.11.0 - 0.16.4
Fixed in 0.16.5
0.17.0 - 0.19.1
Fixed in 0.19.2
0.20.0 - 0.20.1
Fixed in 0.20.2
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to cross-site scripting (XSS) due to improper handling of Unicode normalization in the Action API. This flaw allows attackers to bypass input filters and inject malicious JavaScript, potentially leading to unauthorized script execution in the user's browser.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

wikimedia/parsoid is vulnerable to Cross-site Scripting (XSS) in versions 0.11.0 - 0.16.4, 0.17.0 - 0.19.1 and 0.20.0 - 0.20.1.

How to fix this

Upgrade the wikimedia/parsoid library to the patch version.