VDB
Sign up
HIGH8.7

GHSA-mh5m-5hw4-5c69

TinyMCE Cross-Site Scripting (XSS) vulnerability using sanitization bypass through nested SVGs

Quick fix

GHSA-mh5m-5hw4-5c69 — tinymce: upgrade to the fixed version with the command below.

npm install tinymce@7.1.0

Details

### Impact TinyMCE 6.8.x contains an XSS vulnerability caused by improper SVG namespace scope handling in the sanitizer. A crafted payload using nested <svg> elements can bypass attribute sanitization and execute arbitrary JavaScript.

### Patches This issue affects TinyMCE 6.8.x-7.0.x. The vulnerability is fixed in TinyMCE 7.1.0 and later.

### Workarounds No official workaround available.

### Acknowledgements Tiny thanks [maple3142](https://github.com/maple3142) (<https://maple3142.net>) of DEVCORE for their help identifying this vulnerability.

### References Fix introduced in TinyMCE 7.1.0 though a rewrite of code causing the vulnerability.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/tinymce
Introduced in: 6.8.0Fixed in: 7.1.0
Fixnpm install tinymce@7.1.0
NuGet/TinyMCE
Introduced in: 6.8.0Fixed in: 7.1.0
Fixdotnet add package TinyMCE --version 7.1.0
Packagist/tinymce/tinymce
Introduced in: 6.8.0Fixed in: 7.1.0
Fixcomposer require tinymce/tinymce:^7.1.0

References