GHSA-rgg8-g5x8-wr9v
MODERATECVE-2024-45613During a recent internal audit, we identified a Cross-Site Scripting (XSS) vulnerability in the CKEditor 5 clipboard package. This vulnerability could be triggered by a specific user action, leading to unauthorized JavaScript code execution, if the attacker managed to insert a malicious content into the editor, which might happen with a very specific editor configuration.
- Affected
- >= 40.0.0, < 43.1.1
- Fixed in
- 43.1.1
- Weakness
- CWE-79
- Published
- 2024-09-25
- Source
- github