Intel

AIKIDO-2025-10689

devextreme-quill is vulnerable to Improper Input Validation

Improper Input Validation Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Oct 9, 2025

77

High Risk

This Affects:

JSdevextreme-quill
0.9.0 - 1.6.5
Fixed in 1.6.6
1.7.0 - 1.7.5
Fixed in 1.7.6
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable due to insufficient validation of user-uploaded SVG files. Malicious SVGs can include scripts, event handlers, or external references that execute when rendered, leading to cross-site scripting (XSS), data theft, or phishing. Attackers may also craft SVGs to cause excessive resource consumption and denial-of-service (DoS).

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

devextreme-quill is vulnerable to Improper Input Validation in versions 1.7.0 - 1.7.5 and 0.9.0 - 1.6.5.

How to fix this

Upgrade the devextreme-quill library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform