Vulnerabilities/

@tiptap/extension-link vulnerable to Cross-site Scripting (XSS)

Severity:
Low

Description

Versions of the package @tiptap/extension-link before 2.10.4 are vulnerable to Cross-site Scripting (XSS) due to unsanitized user input allowed in setting or toggling links.

Recommendation

Update the @tiptap/extension-link package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@tiptap/extension-link
Anything's wrong? Let us know Last updated on December 10, 2025