### Impact Stored XSS vulnerability in the media plugin. Attackers can inject malicious scripts via crafted `data-mce-*` attributes, which are executed when content is rendered. Impacts users of TinyMCE with the media plugin enabled. ### Patches This vulnerability has been patched in TinyMCE 8.5.1, TinyMCE 7.9.3 and TinyMCE 5.11.1 LTS by ensuring that, when using the media plugin, any content with `data-mce-object` and `data-mce-p-*` attributes are properly sanitized. ### Workarounds No official workaround available. ### Fix To avoid this vulnerability: - Upgrade to TinyMCE 8.5.1 or higher. - Upgrade to TinyMCE 7.9.3 or higher. - Upgrade to TinyMCE 5.11.1 LTS or higher for TinyMCE 5.x (only available as part of commercial [long-term support](https://www.tiny.cloud/long-term-support/) contract). ### Acknowledgements Tiny thanks [Aymane MAZGUITI](https://github.com/UncleJ4ck) and [Ange Primiterra](https://github.com/ange-primiterra) for their help identifying this vulnerability.
Update tinymce/tinymce to 7.9.3; tinymce/tinymce to 8.5.1; tinymce to 7.9.3; tinymce to 8.5.1; TinyMCE to 8.5.1; TinyMCE to 7.9.3 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanTinyMCE Cross-Site Scripting (XSS) vulnerability using media plugin `data-mce-object` injection affects tinymce/tinymce (composer), tinymce/tinymce (composer), tinymce/tinymce (composer), tinymce/tinymce (composer), tinymce (npm), tinymce (npm), tinymce (npm), tinymce (npm), TinyMCE (nuget), TinyMCE (nuget), TinyMCE (nuget), TinyMCE (nuget). Severity is high. ### Impact Stored XSS vulnerability in the media plugin. Attackers can inject malicious scripts via crafted `data-mce-*` attributes, which are executed when content is rendered. Impacts users of TinyMCE with the media plugin enabled. ### Patches This vulnerability has been patched in TinyMCE 8.5.1, TinyMCE 7.9.3 and TinyMCE 5.11.1 LTS by ensuring that, when using the media plugin, any content with `data-mce-object` and `data-mce-p-*` attributes are properly sanitized. ### Workarounds No official workaround available. ### Fix To avoid this vulnerability: - Upgrade to TinyMCE 8.5.1 or higher. - Upgrade to TinyMCE 7.9.3 or higher. - Upgrade to TinyMCE 5.11.1 LTS or higher for TinyMCE 5.x (only available as part of commercial [long-term support](https://www.tiny.cloud/long-term-support/) contract). ### Acknowledgements Tiny thanks [Aymane MAZGUITI](https://github.com/UncleJ4ck) and [Ange Primiterra](https://github.com/ange-primiterra) for their help identifying this vulnerability.
AI coding agents often install or upgrade packages automatically in composer, npm and nuget. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
### Impact Stored XSS vulnerability in the media plugin. Attackers can inject malicious scripts via crafted `data-mce-*` attributes, which are executed when content is rendered. Impacts users of TinyMCE with the media plugin enabled. ### Patches This vulnerability has been patched in TinyMCE 8.5.1, TinyMCE 7.9.3 and TinyMCE 5.11.1 LTS by ensuring that, when using the media plugin, any content with `data-mce-object` and `data-mce-p-*` attributes are properly sanitized. ### Workarounds No official workaround available. ### Fix To avoid this vulnerability: - Upgrade to TinyMCE 8.5.1 or higher. - Upgrade to TinyMCE 7.9.3 or higher. - Upgrade to TinyMCE 5.11.1 LTS or higher for TinyMCE 5.x (only available as part of commercial [long-term support](https://www.tiny.cloud/long-term-support/) contract). ### Acknowledgements Tiny thanks [Aymane MAZGUITI](https://github.com/UncleJ4ck) and [Ange Primiterra](https://github.com/ange-primiterra) for their help identifying this vulnerability.
Update tinymce/tinymce to 7.9.3; tinymce/tinymce to 8.5.1; tinymce to 7.9.3; tinymce to 8.5.1; TinyMCE to 8.5.1; TinyMCE to 7.9.3 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanTinyMCE Cross-Site Scripting (XSS) vulnerability using media plugin `data-mce-object` injection affects tinymce/tinymce (composer), tinymce/tinymce (composer), tinymce/tinymce (composer), tinymce/tinymce (composer), tinymce (npm), tinymce (npm), tinymce (npm), tinymce (npm), TinyMCE (nuget), TinyMCE (nuget), TinyMCE (nuget), TinyMCE (nuget). Severity is high. ### Impact Stored XSS vulnerability in the media plugin. Attackers can inject malicious scripts via crafted `data-mce-*` attributes, which are executed when content is rendered. Impacts users of TinyMCE with the media plugin enabled. ### Patches This vulnerability has been patched in TinyMCE 8.5.1, TinyMCE 7.9.3 and TinyMCE 5.11.1 LTS by ensuring that, when using the media plugin, any content with `data-mce-object` and `data-mce-p-*` attributes are properly sanitized. ### Workarounds No official workaround available. ### Fix To avoid this vulnerability: - Upgrade to TinyMCE 8.5.1 or higher. - Upgrade to TinyMCE 7.9.3 or higher. - Upgrade to TinyMCE 5.11.1 LTS or higher for TinyMCE 5.x (only available as part of commercial [long-term support](https://www.tiny.cloud/long-term-support/) contract). ### Acknowledgements Tiny thanks [Aymane MAZGUITI](https://github.com/UncleJ4ck) and [Ange Primiterra](https://github.com/ange-primiterra) for their help identifying this vulnerability.
AI coding agents often install or upgrade packages automatically in composer, npm and nuget. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| tinymce/tinymcecomposer | <5.11.1 | Not reported |
| tinymce/tinymcecomposer | >=6.0.0,<7.9.3 | 7.9.3 |
| tinymce/tinymcecomposer | >=8.0.0,<8.5.1 | 8.5.1 |
| tinymce/tinymcecomposer | >0,<=5.10.9 | Not reported |
| tinymcenpm | <5.11.1 | Not reported |
| tinymcenpm | >=6.0.0,<7.9.3 | 7.9.3 |
| tinymcenpm | >=8.0.0,<8.5.1 | 8.5.1 |
| tinymcenpm | >0,<=5.10.9 | Not reported |
| TinyMCEnuget | >=8.0.0,<8.5.1 | 8.5.1 |
| TinyMCEnuget | >0,<=5.10.9 | Not reported |
| TinyMCEnuget | <5.11.1 | Not reported |
| TinyMCEnuget | >=6.0.0,<7.9.3 | 7.9.3 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| Package | Affected range | Fixed version |
|---|---|---|
| tinymce/tinymcecomposer | <5.11.1 | Not reported |
| tinymce/tinymcecomposer | >=6.0.0,<7.9.3 | 7.9.3 |
| tinymce/tinymcecomposer | >=8.0.0,<8.5.1 | 8.5.1 |
| tinymce/tinymcecomposer | >0,<=5.10.9 | Not reported |
| tinymcenpm | <5.11.1 | Not reported |
| tinymcenpm | >=6.0.0,<7.9.3 | 7.9.3 |
| tinymcenpm | >=8.0.0,<8.5.1 | 8.5.1 |
| tinymcenpm | >0,<=5.10.9 | Not reported |
| TinyMCEnuget | >=8.0.0,<8.5.1 | 8.5.1 |
| TinyMCEnuget | >0,<=5.10.9 | Not reported |
| TinyMCEnuget | <5.11.1 | Not reported |
| TinyMCEnuget | >=6.0.0,<7.9.3 | 7.9.3 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard