VDB
Sign up
MEDIUM6.1

GHSA-5h9g-x5rv-25wg

Cross-site scripting vulnerability in TinyMCE

Quick fix

GHSA-5h9g-x5rv-25wg — tinymce: upgrade to the fixed version with the command below.

npm install tinymce@5.9.0

Details

### Impact A cross-site scripting (XSS) vulnerability was discovered in the schema validation logic of the core parser. The vulnerability allowed arbitrary JavaScript execution when inserting a specially crafted piece of content into the editor using the clipboard or editor APIs. This malicious content could then end up in content published outside the editor, if no server-side sanitization was performed. This impacts all users who are using TinyMCE 5.8.2 or lower.

### Patches This vulnerability has been patched in TinyMCE 5.9.0 by ensuring schema validation was still performed after unwrapping invalid elements.

### Workarounds To work around this vulnerability, either: - Upgrade to TinyMCE 5.9.0 or higher - Manually sanitize the content using the `BeforeSetContent` event (see below)

#### Example: Manually sanitize content ```js editor.on('BeforeSetContent', function(e) { var sanitizedContent = ...; // Manually sanitize content here e.content = sanitizedContent; }); ```

### Acknowledgements Tiny Technologies would like to thank William Bowling for discovering this vulnerability.

### References https://www.tiny.cloud/docs/release-notes/release-notes59/#securityfixes

### For more information If you have any questions or comments about this advisory: * Email us at [infosec@tiny.cloud](mailto:infosec@tiny.cloud) * Open an issue in the [TinyMCE repo](https://github.com/tinymce/tinymce/issues)

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/tinymce
Introduced in: 0Fixed in: 5.9.0
Fixnpm install tinymce@5.9.0
NuGet/TinyMCE
Introduced in: 0Fixed in: 5.9.0
Fixdotnet add package TinyMCE --version 5.9.0
Packagist/tinymce/tinymce
Introduced in: 0Fixed in: 5.9.0
Fixcomposer require tinymce/tinymce:^5.9.0

References