Description
ProseMirror's view component renders and manages the editable browser interface for ProseMirror documents. Prior to 1.42.3, prosemirror-view paste handling accepts attacker-provided HTML whose clipboard slice context contains attributes that are not passed through schema attribute validation. When a user pastes the crafted HTML into an editor, the unvalidated context attributes can construct content that executes attacker-controlled JavaScript in the browser window containing the editor. This issue is fixed in version 1.42.3.
Published: 2026-10-02
Score: 8.5 High
EPSS: n/a
KEV: No
Impact: Cross‑Site Scripting (arbitrary client‑side script execution)
Action: Patch now
AI Analysis

Impact

ProseMirror’s view component, responsible for rendering the editable content area, has an identified flaw in its paste handling. Prior to version 1.42.3, the component accepts attacker‑crafted HTML and, while parsing the clipboard slice, includes attributes from the context that are not subject to the editor’s schema attribute validation. When a user pastes such content into an editor instance, the unvalidated attributes enable the injection of malicious JavaScript that runs in the browser that hosts the editor. The vulnerability is a classic cross‑site scripting flaw, classified as CWE‑79, enabling attackers to execute arbitrary code in the victim’s browser, potentially compromising confidentiality, integrity, and user trust.

Affected Systems

The flaw affects ProseMirror’s prosemirror‑view component. All installations of prosemirror‑view older than 1.42.3 are vulnerable. The vulnerability is present in any setup that uses the default paste handling behavior and does not apply a custom schema validation override that rejects the problematic attributes.

Risk and Exploitability

The CVSS score of 8.5 indicates a high severity; however, the EPSS score is not available, so the current exploitation probability is unknown. The vulnerability is not listed in CISA’s KEV inventory. The attack vector is likely a user‑initiated paste action, possibly from a malicious webpage, email, or other user‑provided data source, which can be leveraged to run arbitrary JavaScript in the context of the editor’s host page.

Generated by OpenCVE AI on October 2, 2026 at 17:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade prosemirror‑view to version 1.42.3 or newer. This release removes the ability for unvalidated context attributes to be included when pasting HTML.
  • If an upgrade is not immediately possible, configure the editor to sanitize all pasted content or disable the default paste handler, ensuring only schema‑allowed attributes are accepted. This mitigates the risk of malicious JavaScript execution.
  • Establish a process to monitor ProseMirror releases and regularly review dependencies for similar security advisories, ensuring timely application of future patches.

Generated by OpenCVE AI on October 2, 2026 at 17:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 02 Oct 2026 16:15:00 +0000

Type Values Removed Values Added
Description ProseMirror's view component renders and manages the editable browser interface for ProseMirror documents. Prior to 1.42.3, prosemirror-view paste handling accepts attacker-provided HTML whose clipboard slice context contains attributes that are not passed through schema attribute validation. When a user pastes the crafted HTML into an editor, the unvalidated context attributes can construct content that executes attacker-controlled JavaScript in the browser window containing the editor. This issue is fixed in version 1.42.3.
Title ProseMirror: XSS vulnerability in prosemirror-view's paste handling
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-02T16:57:44.659Z

Reserved: 2026-10-02T14:38:43.243Z

Link: CVE-2026-104847

cve-icon Vulnrichment

Updated: 2026-10-02T16:57:39.636Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-02T16:16:47.410

Modified: 2026-10-02T18:44:11.270

Link: CVE-2026-104847

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T17:30:18Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')