ueberdosis/tiptap-php is vulnerable to Cross-site Scripting (XSS)
51
Medium Risk
Affected versions of this package are vulnerable to Cross-site Scripting (XSS) in anchor tags due to inadequate validation of the href attribute during link rendering. Attackers can exploit this by injecting malicious JavaScript URIs into the href parameter, which executes arbitrary code when users click the compromised link. It occurs because then renderHTML() function merges user-supplied attributes without sanitizing dangerous URL schemes, allowing DOM-based XSS attacks. Successful exploitation could lead to stolen sessions, redirecting users, or performing actions on behalf of authenticated victims.
You are affected if you are using a version that falls within the vulnerable range.
ueberdosis/tiptap-php is vulnerable to Cross-site Scripting (XSS) in versions 1.0.0 - 1.4.0.
Upgrade the ueberdosis/tiptap-php library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant