Intel

AIKIDO-2025-10517

md-editor-v3 is vulnerable to Cross-site Scripting (XSS)

Cross-site Scripting (XSS) Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jul 31, 2025

59

Medium Risk

This Affects:

jsmd-editor-v3
4.15.0 - 5.8.2
Fixed in 5.8.3
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to cross-site scripting (XSS) when rendering code blocks due to insufficient sanitization of user input. Malicious content embedded within code blocks may be interpreted and executed by the browser, allowing attackers to inject arbitrary scripts and potentially compromise user sessions or perform unauthorized actions. Proper input sanitization is required to ensure code blocks are safely rendered as plain text without executing embedded HTML or JavaScript.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

md-editor-v3 is vulnerable to Cross-site Scripting (XSS) in versions 4.15.0 - 5.8.2.

How to fix this

Upgrade the md-editor-v3 library to the patch version.