GHSA-h3pq-667x-r789
HIGHCVE-2024-40631Editors that use MediaEmbedElement and pass custom urlParsers to the useMediaState hook may be vulnerable to XSS if a custom parser allows javascript:, data: or vbscript: URLs to be embedded. Editors that do not use urlParsers and instead consume the url property directly may also be vulnerable if the URL is not sanitised.
- Affected
- < 36.0.10
- Fixed in
- 36.0.10
- Weakness
- CWE-79
- Published
- 2024-07-15
- Source
- github