MEDIUM 6.1
GHSA-42hx-vrxx-5r6v
Jodit Editor vulnerable to Cross-site Scripting
Details
Jodit Editor is a WYSIWYG editor written in pure TypeScript without the use of additional libraries. Jodit Editor is vulnerable to XSS attacks when pasting specially constructed input. This issue has not been fully patched. There are no known workarounds.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm / jodit
Introduced in:
0 No fixed version published yet for jodit (npm). Pin to a known-safe version or switch to an alternative.