### Impact Stored XSS vulnerability via unsanitized data-mce-* attributes (data-mce-href, data-mce-src, data-mce-style). Allows attackers to inject malicious values that override safe attributes during serialization, bypassing validation. ### Patches Patched by stripping unsafe data-mce-* attributes during parsing. Users should upgrade to the latest patched versions (5 LTS, 7.x, 8.x). ### Workarounds No official workaround available. ### Fix To avoid this vulnerability: Upgrade to TinyMCE 8.5.1 or higher. Upgrade to TinyMCE 7.9.3 or higher. Upgrade to TinyMCE 5.11.1 LTS or higher for TinyMCE 5.x (only available as part of commercial [long-term support](https://www.tiny.cloud/long-term-support/) contract). ### Acknowledgements Tiny thanks [Tadi Kadango](https://github.com/mtrill47) ([website](https://tadiwakadango.com/)) and [Ivan Babenko](https://github.com/he1d3n) for their help identifying this vulnerability.
Update tinymce/tinymce to 7.9.3; tinymce/tinymce to 8.5.1; tinymce to 7.9.3; tinymce to 8.5.1; TinyMCE to 5.11.1; TinyMCE to 7.9.3; TinyMCE to 8.5.1 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanTinyMCE Cross-Site Scripting (XSS) vulnerability using through data-mce- prefixed src, href, style attributes affects tinymce/tinymce (composer), tinymce/tinymce (composer), tinymce/tinymce (composer), tinymce/tinymce (composer), tinymce (npm), tinymce (npm), tinymce (npm), tinymce (npm), TinyMCE (nuget), TinyMCE (nuget), TinyMCE (nuget), TinyMCE (nuget). Severity is high. ### Impact Stored XSS vulnerability via unsanitized data-mce-* attributes (data-mce-href, data-mce-src, data-mce-style). Allows attackers to inject malicious values that override safe attributes during serialization, bypassing validation. ### Patches Patched by stripping unsafe data-mce-* attributes during parsing. Users should upgrade to the latest patched versions (5 LTS, 7.x, 8.x). ### Workarounds No official workaround available. ### Fix To avoid this vulnerability: Upgrade to TinyMCE 8.5.1 or higher. Upgrade to TinyMCE 7.9.3 or higher. Upgrade to TinyMCE 5.11.1 LTS or higher for TinyMCE 5.x (only available as part of commercial [long-term support](https://www.tiny.cloud/long-term-support/) contract). ### Acknowledgements Tiny thanks [Tadi Kadango](https://github.com/mtrill47) ([website](https://tadiwakadango.com/)) and [Ivan Babenko](https://github.com/he1d3n) for their help identifying this vulnerability.
AI coding agents often install or upgrade packages automatically in composer, npm and nuget. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
### Impact Stored XSS vulnerability via unsanitized data-mce-* attributes (data-mce-href, data-mce-src, data-mce-style). Allows attackers to inject malicious values that override safe attributes during serialization, bypassing validation. ### Patches Patched by stripping unsafe data-mce-* attributes during parsing. Users should upgrade to the latest patched versions (5 LTS, 7.x, 8.x). ### Workarounds No official workaround available. ### Fix To avoid this vulnerability: Upgrade to TinyMCE 8.5.1 or higher. Upgrade to TinyMCE 7.9.3 or higher. Upgrade to TinyMCE 5.11.1 LTS or higher for TinyMCE 5.x (only available as part of commercial [long-term support](https://www.tiny.cloud/long-term-support/) contract). ### Acknowledgements Tiny thanks [Tadi Kadango](https://github.com/mtrill47) ([website](https://tadiwakadango.com/)) and [Ivan Babenko](https://github.com/he1d3n) for their help identifying this vulnerability.
Update tinymce/tinymce to 7.9.3; tinymce/tinymce to 8.5.1; tinymce to 7.9.3; tinymce to 8.5.1; TinyMCE to 5.11.1; TinyMCE to 7.9.3; TinyMCE to 8.5.1 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanTinyMCE Cross-Site Scripting (XSS) vulnerability using through data-mce- prefixed src, href, style attributes affects tinymce/tinymce (composer), tinymce/tinymce (composer), tinymce/tinymce (composer), tinymce/tinymce (composer), tinymce (npm), tinymce (npm), tinymce (npm), tinymce (npm), TinyMCE (nuget), TinyMCE (nuget), TinyMCE (nuget), TinyMCE (nuget). Severity is high. ### Impact Stored XSS vulnerability via unsanitized data-mce-* attributes (data-mce-href, data-mce-src, data-mce-style). Allows attackers to inject malicious values that override safe attributes during serialization, bypassing validation. ### Patches Patched by stripping unsafe data-mce-* attributes during parsing. Users should upgrade to the latest patched versions (5 LTS, 7.x, 8.x). ### Workarounds No official workaround available. ### Fix To avoid this vulnerability: Upgrade to TinyMCE 8.5.1 or higher. Upgrade to TinyMCE 7.9.3 or higher. Upgrade to TinyMCE 5.11.1 LTS or higher for TinyMCE 5.x (only available as part of commercial [long-term support](https://www.tiny.cloud/long-term-support/) contract). ### Acknowledgements Tiny thanks [Tadi Kadango](https://github.com/mtrill47) ([website](https://tadiwakadango.com/)) and [Ivan Babenko](https://github.com/he1d3n) for their help identifying this vulnerability.
AI coding agents often install or upgrade packages automatically in composer, npm and nuget. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| tinymce/tinymcecomposer | <5.11.1 | Not reported |
| tinymce/tinymcecomposer | >=6.0.0,<7.9.3 | 7.9.3 |
| tinymce/tinymcecomposer | >=8.0.0,<8.5.1 | 8.5.1 |
| tinymce/tinymcecomposer | <=5.10.9 | Not reported |
| tinymcenpm | <5.11.1 | Not reported |
| tinymcenpm | >=6.0.0,<7.9.3 | 7.9.3 |
| tinymcenpm | >=8.0.0,<8.5.1 | 8.5.1 |
| tinymcenpm | <=5.10.9 | Not reported |
| TinyMCEnuget | <5.11.1 | 5.11.1 |
| TinyMCEnuget | >=6.0.0,<7.9.3 | 7.9.3 |
| TinyMCEnuget | >=8.0.0,<8.5.1 | 8.5.1 |
| TinyMCEnuget | <=5.10.9 | Not reported |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| Package | Affected range | Fixed version |
|---|---|---|
| tinymce/tinymcecomposer | <5.11.1 | Not reported |
| tinymce/tinymcecomposer | >=6.0.0,<7.9.3 | 7.9.3 |
| tinymce/tinymcecomposer | >=8.0.0,<8.5.1 | 8.5.1 |
| tinymce/tinymcecomposer | <=5.10.9 | Not reported |
| tinymcenpm | <5.11.1 | Not reported |
| tinymcenpm | >=6.0.0,<7.9.3 | 7.9.3 |
| tinymcenpm | >=8.0.0,<8.5.1 | 8.5.1 |
| tinymcenpm | <=5.10.9 | Not reported |
| TinyMCEnuget | <5.11.1 | 5.11.1 |
| TinyMCEnuget | >=6.0.0,<7.9.3 | 7.9.3 |
| TinyMCEnuget | >=8.0.0,<8.5.1 | 8.5.1 |
| TinyMCEnuget | <=5.10.9 | Not reported |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard