Intel

AIKIDO-2025-10689

devextreme-quill is vulnerable to Improper Input Validation

Improper Input Validation Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Oct 9, 2025

77

High Risk

This Affects:

JSdevextreme-quill
0.9.0 - 1.6.5
Fixed in 1.6.6
1.7.0 - 1.7.5
Fixed in 1.7.6
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable due to insufficient validation of user-uploaded SVG files. Malicious SVGs can include scripts, event handlers, or external references that execute when rendered, leading to cross-site scripting (XSS), data theft, or phishing. Attackers may also craft SVGs to cause excessive resource consumption and denial-of-service (DoS).

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

devextreme-quill is vulnerable to Improper Input Validation in versions 1.7.0 - 1.7.5 and 0.9.0 - 1.6.5.

How to fix this

Upgrade the devextreme-quill library to the patch version.