npm package report

Is prosemirror-view safe?

1 known vulnerability, worst severity HIGH.

// reach

0 direct dependencies

none carry a known advisory

    11 packages depend on it

    an advisory here reaches each of them

    Create a free accountfor every dependency path, dependent and what to upgrade
    // ai model usage

    Tracked for PyPI packages. HuggingFace models declare Python dependencies, so npm packages are not covered.


    cvss
    0.0
    high

    severity out of 10

    epss
    0.00%
    low

    chance of exploitation in 30 days, 21st percentile of all CVEs

    xyz score
    not scored

    CyberXYZ composite out of 10

    fig. 01 — GHSA-c8x8-7fp4-3x9w, the advisory selected below

    // 1 advisories

    GHSA-c8x8-7fp4-3x9w

    HIGHCVE-2026-104847
    // impact

    When a user pastes attacker-provided HTML into a ProseMirror editor component, this can cause attacker-controlled JavaScript code to run in the browser window containing the editor.

    // patches

    Version 1.42.3 adds validation that prevents this attack.

    // workarounds

    No known workarounds.

    // cvss v4.0 vector

    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

    Attack vector
    Network
    Attack complexity
    Low
    Attack requirements
    None
    Privileges required
    None
    User interaction
    Active
    Confidentiality (vulnerable system)
    High
    Integrity (vulnerable system)
    High
    Availability (vulnerable system)
    None
    Confidentiality (subsequent systems)
    None
    Integrity (subsequent systems)
    None
    Availability (subsequent systems)
    None

    Checked 2026-10-06 at 02:02 UTC. The most recent advisory here was published 2026-10-05. Updated continuously from NVD, GHSA, OSV and CNA feeds.

    Think a verdict here is wrong? Tell us — we respond within 2 business days.