GHSA-x9gp-vjh6-3wv6

Suggest an improvement
Source
https://github.com/advisories/GHSA-x9gp-vjh6-3wv6
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-x9gp-vjh6-3wv6/GHSA-x9gp-vjh6-3wv6.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-x9gp-vjh6-3wv6
Aliases
Published
2025-09-03T18:03:20Z
Modified
2025-09-04T13:51:52Z
Severity
  • 2.3 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N CVSS Calculator
Summary
CKEditor 5 cross-site scripting (XSS) vulnerability in the clipboard package
Details

Impact

A Cross-Site Scripting (XSS) vulnerability has been discovered in the CKEditor 5 clipboard package. This vulnerability could be triggered by a specific user action, leading to unauthorized JavaScript code execution, if the attacker managed to insert a malicious content into the editor, which might happen with a very specific editor configuration.

This vulnerability affects only installations where the editor configuration meets one of the following criteria:

Patches

The problem has been recognized and patched. The fix will be available in version 46.0.3 (and above), and explicitly in version 45.2.2.

For more information

Email us at security@cksource.com if you have any questions or comments about this advisory.

Database specific
{
    "cwe_ids":  [
        "CWE-79"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2025-09-03T18:03:20Z",
    "nvd_published_at":  "2025-09-04T10:42:32Z",
    "severity":  "LOW"
}
References

Affected packages

npm / ckeditor5

Package

Affected ranges

Type
SEMVER
Events
Introduced
46.0.0
Fixed
46.0.3

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-x9gp-vjh6-3wv6/GHSA-x9gp-vjh6-3wv6.json"

npm / @ckeditor/ckeditor5-clipboard

Package

Name
@ckeditor/ckeditor5-clipboard
View open source insights on deps.dev
Purl
pkg:npm/%40ckeditor/ckeditor5-clipboard

Affected ranges

Type
SEMVER
Events
Introduced
44.2.0
Fixed
45.2.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-x9gp-vjh6-3wv6/GHSA-x9gp-vjh6-3wv6.json"

npm / ckeditor5

Package

Affected ranges

Type
SEMVER
Events
Introduced
44.2.0
Fixed
45.2.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-x9gp-vjh6-3wv6/GHSA-x9gp-vjh6-3wv6.json"

npm / @ckeditor/ckeditor5-clipboard

Package

Name
@ckeditor/ckeditor5-clipboard
View open source insights on deps.dev
Purl
pkg:npm/%40ckeditor/ckeditor5-clipboard

Affected ranges

Type
SEMVER
Events
Introduced
46.0.0
Fixed
46.0.3

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-x9gp-vjh6-3wv6/GHSA-x9gp-vjh6-3wv6.json"