Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 02 Oct 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 02 Oct 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ProseMirror's view component renders and manages the editable browser interface for ProseMirror documents. Prior to 1.42.3, prosemirror-view paste handling accepts attacker-provided HTML whose clipboard slice context contains attributes that are not passed through schema attribute validation. When a user pastes the crafted HTML into an editor, the unvalidated context attributes can construct content that executes attacker-controlled JavaScript in the browser window containing the editor. This issue is fixed in version 1.42.3. | |
| Title | ProseMirror: XSS vulnerability in prosemirror-view's paste handling | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-02T16:57:44.659Z
Reserved: 2026-10-02T14:38:43.243Z
Link: CVE-2026-104847
Updated: 2026-10-02T16:57:39.636Z
Status : Awaiting Analysis
Published: 2026-10-02T16:16:47.410
Modified: 2026-10-02T18:44:11.270
Link: CVE-2026-104847
No data.
OpenCVE Enrichment
Updated: 2026-10-02T17:30:18Z