When a user pastes attacker-provided HTML into a ProseMirror editor component, this can cause attacker-controlled JavaScript code to run in the browser window containing the editor.
Version 1.42.3 adds validation that prevents this attack.
No known workarounds.
{
"cwe_ids": [
"CWE-79"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-05T22:36:06Z",
"nvd_published_at": "2026-10-02T16:16:47Z",
"severity": "HIGH"
}