Vulnerabilities/

Editor.js vulnerable to Code Injection

Severity:
Medium

Description

Editor.js is a block-style editor with clean JSON output. Versions prior to 2.26.0 are vulnerable to Code Injection via pasted input. The processHTML method passes pasted input into wrapper’s innerHTML. This issue is patched in version 2.26.0.

Recommendation

Update the @editorjs/editorjs package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@editorjs/editorjs
Anything's wrong? Let us know Last updated on August 05, 2024