GHSA-c8x8-7fp4-3x9wHigh

ProseMirror has a XSS vulnerability in prosemirror-view's paste handling

Published
October 5, 2026
Last Modified
October 5, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

When a user pastes attacker-provided HTML into a ProseMirror editor component, this can cause attacker-controlled JavaScript code to run in the browser window containing the editor.

Patches

Version 1.42.3 adds validation that prevents this attack.

Workarounds

No known workarounds.

🎯 Affected products1

  • npm/prosemirror-view:< 1.42.3

🔗 References (5)