tiptap@1.23.5 vulnerabilities

A rich-text editor for Vue.js

Direct Vulnerabilities

Known vulnerabilities in the tiptap package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Cross-site Scripting (XSS)

tiptap is an A rich-text editor for Vue.js

Affected versions of this package are vulnerable to Cross-site Scripting (XSS). When using the editor and importing data which was stored as raw HTML string (usually by getHTML() function) it is possible to inject javascript code there and create a stored XSS in the application using the editor.

How to fix Cross-site Scripting (XSS)?

Upgrade tiptap to version 1.29.0 or higher.

<1.29.0