@tiptap/core is vulnerable to Cross-Site Scripting (XSS)
72
High Risk
Affected versions of this package are vulnerable to Cross-Site Scripting (XSS) through the mergeAttributes() helper, which assigns keys from untrusted attribute objects without filtering. Processing content that carries a __proto__ key invokes the legacy prototype setter and pollutes the merged object's prototype with externally controlled values. When that object is later serialized as a ProseMirror DOMOutputSpec, the inherited properties are applied as DOM attributes. The fix defines the copied key as an own data property so untrusted input can no longer alter the object's prototype.
You are affected if you are using a version in the vulnerable range and your application merges untrusted or externally influenced attribute objects through mergeAttributes(), whose result is later serialized into the DOM.
@tiptap/core is vulnerable to Cross-Site Scripting (XSS) in versions 2.0.0 - 3.30.3.
Upgrade the @tiptap/core library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.