-
Notifications
You must be signed in to change notification settings - Fork 210
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
TinyMCE Cross-Site Scripting (XSS) vulnerability #407
Comments
There is a lot more vulnerabilities would be nice to get update to |
We are working on an update to the vue package. |
@Afraithe Awesome, can't wait! |
@Afraithe any word on a new version? |
Looks like this issue should be resolved with #408 |
This issue is stale because it has been open 30 days with no activity. Please comment if you wish to keep this issue open or it will be closed in 7 days. |
This has now been fixed in a recent release, closing. |
Hi! Just reaching out about the update status of tinymce-vue. Got a heads up from npm today about an XSS bug in TinyMCE, set to be fixed in version 7.0.
TinyMCE Cross-Site Scripting (XSS) vulnerability in handling external SVG files through Object or Embed elements - https://github.com/advisories/GHSA-5359-pvf2-pw78
If there's any chance we'll see an update roll out soon to address this?
Thanks a bunch!
The text was updated successfully, but these errors were encountered: