tinymce-vue icon indicating copy to clipboard operation
tinymce-vue copied to clipboard

TinyMCE Cross-Site Scripting (XSS) vulnerability

Open kburisma opened this issue 10 months ago • 5 comments

Hi! Just reaching out about the update status of tinymce-vue. Got a heads up from npm today about an XSS bug in TinyMCE, set to be fixed in version 7.0.

TinyMCE Cross-Site Scripting (XSS) vulnerability in handling external SVG files through Object or Embed elements - https://github.com/advisories/GHSA-5359-pvf2-pw78

If there's any chance we'll see an update roll out soon to address this?

Thanks a bunch!

kburisma avatar Apr 10 '24 15:04 kburisma