Overview
About vulnerability
Impact
TinyMCE 6.8.x contains an XSS vulnerability caused by improper SVG namespace scope handling in the sanitizer. A crafted payload using nested <svg> elements can bypass attribute sanitization and execute arbitrary JavaScript.
Patches
This issue affects TinyMCE 6.8.x-7.0.x. The vulnerability is fixed in TinyMCE 7.1.0 and later.
Workarounds
No official workaround available.
Acknowledgements
Tiny thanks [maple3142](https://github.com/maple3142) (<https://maple3142.net>) of DEVCORE for their help identifying this vulnerability.
References
Fix introduced in TinyMCE 7.1.0 though a rewrite of code causing the vulnerability.
Details
- Affected product:
- tinymce
- Affected packages:
- tinymce @ 6.8.6