Description
react-draft-wysiwyg (aka React Draft Wysiwyg) before 1.14.6 allows a javascript: URi in a Link Target of the link decorator in decorators/Link/index.js when a draft is shared across users, leading to XSS.
Recommendation
Update the react-draft-wysiwyg package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.14.6
- Patched version(s): 1.14.6
References
Related Issues
- React Draft Wysiwyg Cross-Site Scripting (XSS) via the Embedded Button - CVE-2025-3191
- Cross-site scripting in react-bootstrap-table - CVE-2021-23398
- Cross-site scripting in anchorme - CVE-2021-23411
- Cross-Site Scripting in react - react - CVE-2013-7035
You might also like:
- Tags:
- npm
- react-draft-wysiwyg
Anything's wrong? Let us know Last updated on September 11, 2023


