Description
A regex denial of service (ReDoS) vulnerability was discovered in a dependency of the codesample plugin. The vulnerability allowed poorly formed ruby code samples to lock up the browser while performing syntax highlighting. This impacts users of the codesample plugin using TinyMCE 5.5.1 or lower.
Recommendation
Update the tinymce package to the latest compatible version. Followings are version details:
- Affected version(s): < 5.6.0
- Patched version(s): 5.6.0
References
Related Issues
- string-math's string-math.js vulnerability can cause Regex Denial of Service (ReDoS) - CVE-2025-45143
- TinyMCE mXSS vulnerability in undo/redo, getContent API, resetContent API, and Autosave plugin - CVE-2023-45818
- Regular Expression Denial of Service in underscore.string - Vulnerability
- Denial of Service (DoS) vulnerability in RSSHub - CVE-2022-31110
You might also like:
- Tags:
- npm
- tinymce
Anything's wrong? Let us know Last updated on January 09, 2023


