PT-2025-36639 · Npm · @Ckeditor/Ckeditor5-Clipboard+1

Published

2025-09-03

·

Updated

2025-09-03

CVSS v4.0

2.3

Low

VectorAV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N

Impact

A Cross-Site Scripting (XSS) vulnerability has been discovered in the CKEditor 5 clipboard package. This vulnerability could be triggered by a specific user action, leading to unauthorized JavaScript code execution, if the attacker managed to insert a malicious content into the editor, which might happen with a very specific editor configuration.
This vulnerability affects only installations where the editor configuration meets one of the following criteria:

Patches

The problem has been recognized and patched. The fix will be available in version 46.0.3 (and above), and explicitly in version 45.2.2.

For more information

Email us at security@cksource.com if you have any questions or comments about this advisory.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-X9GP-VJH6-3WV6

Affected Products

@Ckeditor/Ckeditor5-Clipboard
Ckeditor 5