Description
A regex denial of service (ReDoS) vulnerability was discovered in a dependency of the codesample plugin. The vulnerability allowed poorly formed ruby code samples to lock up the browser while performing syntax highlighting. This impacts users of the codesample plugin using TinyMCE 5.5.1 or lower.
Recommendation
Update the tinymce package to the latest compatible version. Followings are version details:
- Affected version(s): < 5.6.0
- Patched version(s): 5.6.0
References
Could your website be exposed too?
SmartScanner can check your website for Regex denial of service vulnerability in codesample plugin and gives you actionable findings to investigate.
Start a free scanRelated Issues
- string-math's string-math.js vulnerability can cause Regex Denial of Service (ReDoS) - CVE-2025-45143
- TinyMCE mXSS vulnerability in undo/redo, getContent API, resetContent API, and Autosave plugin - CVE-2023-45818
- Regular Expression Denial of Service in underscore.string - Vulnerability
- Denial of Service (DoS) vulnerability in RSSHub - CVE-2022-31110


