Impact
ProseMirror’s view component, responsible for rendering the editable content area, has an identified flaw in its paste handling. Prior to version 1.42.3, the component accepts attacker‑crafted HTML and, while parsing the clipboard slice, includes attributes from the context that are not subject to the editor’s schema attribute validation. When a user pastes such content into an editor instance, the unvalidated attributes enable the injection of malicious JavaScript that runs in the browser that hosts the editor. The vulnerability is a classic cross‑site scripting flaw, classified as CWE‑79, enabling attackers to execute arbitrary code in the victim’s browser, potentially compromising confidentiality, integrity, and user trust.
Affected Systems
The flaw affects ProseMirror’s prosemirror‑view component. All installations of prosemirror‑view older than 1.42.3 are vulnerable. The vulnerability is present in any setup that uses the default paste handling behavior and does not apply a custom schema validation override that rejects the problematic attributes.
Risk and Exploitability
The CVSS score of 8.5 indicates a high severity; however, the EPSS score is not available, so the current exploitation probability is unknown. The vulnerability is not listed in CISA’s KEV inventory. The attack vector is likely a user‑initiated paste action, possibly from a malicious webpage, email, or other user‑provided data source, which can be leveraged to run arbitrary JavaScript in the context of the editor’s host page.
OpenCVE Enrichment