Description
Versions of status-board prior to 10.0.1 are vulnerable to Cross-Site Scripting. The _createPreviewButton() function fails to sanitize the href attribute of a created <a> tag. This may allow attackers to execute arbitrary JavaScript in a victim’s browser.
Recommendation
Update the @ckeditor/ckeditor5-link package to the latest compatible version. Followings are version details:
- Affected version(s): >= 0.3.0, < 10.0.1
- Patched version(s): 10.0.1
References
- GHSA-gvpx-9459-w3mj
- ckeditor.com
- snyk.io
- www.npmjs.com
- CVE-2018-11093
- CWE-79
- CAPEC-310
- OWASP 2021-A3
- OWASP 2021-A6
Related Issues
- CKEditor5 cross-site scripting vulnerability caused by the editor instance destroying process - @ckeditor/ckeditor5-markdown-gfm - CVE-2022-31175
- CKEditor5 cross-site scripting vulnerability caused by the editor instance destroying process - @ckeditor/ckeditor5-html-support - CVE-2022-31175
- Enhanced Image plugin for CKEditor is vulnerable to Cross-site scripting (XSS) - CVE-2018-9861
- CKEditor 5 cross-site scripting (XSS) vulnerability in the clipboard package - ckeditor5 - CVE-2025-58064
You might also like:
- Tags:
- npm
- @ckeditor/ckeditor5-link
Anything's wrong? Let us know Last updated on May 01, 2023


