PT-2024-28949 · Unknown · Prosemirror

Rskvp93

·

Published

2024-07-16

·

Updated

2026-01-28

·

CVE-2024-40626

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Outline versions prior to 0.77.3
Description A type confusion issue in ProseMirror's rendering process leads to a Stored Cross-Site Scripting (XSS) issue. An authenticated user can create a document with a malicious JavaScript payload, which can execute when other users view the document. The issue can bypass Content Security Policy (CSP) restrictions in self-hosted environments with file storage on the same domain.
Recommendations For versions prior to 0.77.3, upgrade to release version 0.77.3 to address the issue.

Exploit

Fix

DoS

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-40626
GHSA-888C-MVG8-V6WH

Affected Products

Prosemirror