Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

TinyMCE Cross-Site Scripting (XSS) vulnerability #407

Closed
kburisma opened this issue Apr 10, 2024 · 7 comments
Closed

TinyMCE Cross-Site Scripting (XSS) vulnerability #407

kburisma opened this issue Apr 10, 2024 · 7 comments
Labels
status:stale An issue that has been left with no response for an extended period of time.

Comments

@kburisma
Copy link

Hi! Just reaching out about the update status of tinymce-vue. Got a heads up from npm today about an XSS bug in TinyMCE, set to be fixed in version 7.0.

TinyMCE Cross-Site Scripting (XSS) vulnerability in handling external SVG files through Object or Embed elements - https://github.com/advisories/GHSA-5359-pvf2-pw78

If there's any chance we'll see an update roll out soon to address this?

Thanks a bunch!

@Edgaraszs
Copy link

There is a lot more vulnerabilities would be nice to get update to 7.0

@Afraithe
Copy link
Member

We are working on an update to the vue package.

@meirroth
Copy link

meirroth commented May 6, 2024

@Afraithe Awesome, can't wait!

@719media
Copy link

@Afraithe any word on a new version?

@meirroth
Copy link

meirroth commented Jun 5, 2024

Looks like this issue should be resolved with #408

@tiny-stale-bot
Copy link

This issue is stale because it has been open 30 days with no activity. Please comment if you wish to keep this issue open or it will be closed in 7 days.

@tiny-stale-bot tiny-stale-bot added the status:stale An issue that has been left with no response for an extended period of time. label Jul 9, 2024
@danoaky-tiny
Copy link
Contributor

This has now been fixed in a recent release, closing.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
status:stale An issue that has been left with no response for an extended period of time.
Projects
None yet
Development

No branches or pull requests

7 participants