PT-2025-46205 · Unknown · Prosemirror To Html

Published

2025-11-06

·

Updated

2025-11-11

·

CVE-2025-64501

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions ProsemirrorToHtml versions 0.2.0 and below
Description The prosemirror to html gem contains a flaw that allows for Cross-Site Scripting (XSS) attacks. This is due to improper handling of HTML attribute values during the conversion of ProseMirror-compatible JSON to HTML. While the content of HTML tags is correctly escaped, attribute values are not, enabling attackers to inject arbitrary JavaScript code. Applications utilizing prosemirror to html to convert ProseMirror documents to HTML, particularly those handling user-generated content, and end users viewing the resulting HTML output are potentially at risk.
Recommendations Update to version 0.2.1 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-64501
GHSA-52C5-VH7F-26FX

Affected Products

Prosemirror To Html