VDB
Sign up
MEDIUM6.5

GHSA-588m-9qg5-35pq

Reverse Tabnabbing in quill

Quick fix

GHSA-588m-9qg5-35pq — quill: upgrade to the fixed version with the command below.

npm install quill@1.3.7

Details

Versions of `quill` prior to 1.3.7 are vulnerable to [Reverse Tabnabbing](https://www.owasp.org/index.php/Reverse_Tabnabbing). The package uses `target='_blank'` in anchor tags, allowing attackers to access `window.opener` for the original page when opening links. This is commonly used for phishing attacks.

## Recommendation

No fix is currently available. Consider using an alternative package until a fix is made available.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/quill
Introduced in: 0Fixed in: 1.3.7
Fixnpm install quill@1.3.7

References