### Impact Stored XSS vulnerability via forged mce:protected comments. Allows attackers to bypass sanitization and inject scripts that execute when content is restored. Impacts users who utilize the protect option. ### Patches Patched by validating decoded mce:protected content against configured protect regex rules before restoring. Users should upgrade to the latest patched version. ### Workarounds No official workaround available. ### Fix To avoid this vulnerability: Upgrade to TinyMCE 8.5.1 or higher. Upgrade to TinyMCE 7.9.3 or higher. Upgrade to TinyMCE 5.11.1 LTS or higher for TinyMCE 5.x (only available as part of commercial [long-term support](https://www.tiny.cloud/long-term-support/) contract). ### Acknowledgements Tiny thanks [Ivan Babenko](https://github.com/he1d3n) for their help identifying this vulnerability.
Update tinymce/tinymce to 7.9.3; tinymce/tinymce to 8.5.1; tinymce to 7.9.3; tinymce to 8.5.1; TinyMCE to 7.9.3; TinyMCE to 8.5.1 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanTinyMCE Cross-Site Scripting (XSS) vulnerability through `mce:protected` comments affects tinymce/tinymce (composer), tinymce/tinymce (composer), tinymce/tinymce (composer), tinymce/tinymce (composer), tinymce (npm), tinymce (npm), tinymce (npm), tinymce (npm), TinyMCE (nuget), TinyMCE (nuget), TinyMCE (nuget), TinyMCE (nuget). Severity is high. ### Impact Stored XSS vulnerability via forged mce:protected comments. Allows attackers to bypass sanitization and inject scripts that execute when content is restored. Impacts users who utilize the protect option. ### Patches Patched by validating decoded mce:protected content against configured protect regex rules before restoring. Users should upgrade to the latest patched version. ### Workarounds No official workaround available. ### Fix To avoid this vulnerability: Upgrade to TinyMCE 8.5.1 or higher. Upgrade to TinyMCE 7.9.3 or higher. Upgrade to TinyMCE 5.11.1 LTS or higher for TinyMCE 5.x (only available as part of commercial [long-term support](https://www.tiny.cloud/long-term-support/) contract). ### Acknowledgements Tiny thanks [Ivan Babenko](https://github.com/he1d3n) for their help identifying this vulnerability.
AI coding agents often install or upgrade packages automatically in composer, npm and nuget. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
### Impact Stored XSS vulnerability via forged mce:protected comments. Allows attackers to bypass sanitization and inject scripts that execute when content is restored. Impacts users who utilize the protect option. ### Patches Patched by validating decoded mce:protected content against configured protect regex rules before restoring. Users should upgrade to the latest patched version. ### Workarounds No official workaround available. ### Fix To avoid this vulnerability: Upgrade to TinyMCE 8.5.1 or higher. Upgrade to TinyMCE 7.9.3 or higher. Upgrade to TinyMCE 5.11.1 LTS or higher for TinyMCE 5.x (only available as part of commercial [long-term support](https://www.tiny.cloud/long-term-support/) contract). ### Acknowledgements Tiny thanks [Ivan Babenko](https://github.com/he1d3n) for their help identifying this vulnerability.
Update tinymce/tinymce to 7.9.3; tinymce/tinymce to 8.5.1; tinymce to 7.9.3; tinymce to 8.5.1; TinyMCE to 7.9.3; TinyMCE to 8.5.1 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanTinyMCE Cross-Site Scripting (XSS) vulnerability through `mce:protected` comments affects tinymce/tinymce (composer), tinymce/tinymce (composer), tinymce/tinymce (composer), tinymce/tinymce (composer), tinymce (npm), tinymce (npm), tinymce (npm), tinymce (npm), TinyMCE (nuget), TinyMCE (nuget), TinyMCE (nuget), TinyMCE (nuget). Severity is high. ### Impact Stored XSS vulnerability via forged mce:protected comments. Allows attackers to bypass sanitization and inject scripts that execute when content is restored. Impacts users who utilize the protect option. ### Patches Patched by validating decoded mce:protected content against configured protect regex rules before restoring. Users should upgrade to the latest patched version. ### Workarounds No official workaround available. ### Fix To avoid this vulnerability: Upgrade to TinyMCE 8.5.1 or higher. Upgrade to TinyMCE 7.9.3 or higher. Upgrade to TinyMCE 5.11.1 LTS or higher for TinyMCE 5.x (only available as part of commercial [long-term support](https://www.tiny.cloud/long-term-support/) contract). ### Acknowledgements Tiny thanks [Ivan Babenko](https://github.com/he1d3n) for their help identifying this vulnerability.
AI coding agents often install or upgrade packages automatically in composer, npm and nuget. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|
| tinymce/tinymcecomposer | <5.11.1 | Not reported |
|---|---|---|
| tinymce/tinymcecomposer | >=6.0.0,<7.9.3 | 7.9.3 |
| tinymce/tinymcecomposer | >=8.0.0,<8.5.1 | 8.5.1 |
| tinymce/tinymcecomposer | <=5.10.9 | Not reported |
| tinymcenpm | <5.11.1 | Not reported |
| tinymcenpm | >=6.0.0,<7.9.3 | 7.9.3 |
| tinymcenpm | >=8.0.0,<8.5.1 | 8.5.1 |
| tinymcenpm | <=5.10.9 | Not reported |
| TinyMCEnuget | <5.11.1 | Not reported |
| TinyMCEnuget | >=6.0.0,<7.9.3 | 7.9.3 |
| TinyMCEnuget | >=8.0.0,<8.5.1 | 8.5.1 |
| TinyMCEnuget | <=5.10.9 | Not reported |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| Package | Affected range | Fixed version |
|---|
| tinymce/tinymcecomposer | <5.11.1 | Not reported |
|---|---|---|
| tinymce/tinymcecomposer | >=6.0.0,<7.9.3 | 7.9.3 |
| tinymce/tinymcecomposer | >=8.0.0,<8.5.1 | 8.5.1 |
| tinymce/tinymcecomposer | <=5.10.9 | Not reported |
| tinymcenpm | <5.11.1 | Not reported |
| tinymcenpm | >=6.0.0,<7.9.3 | 7.9.3 |
| tinymcenpm | >=8.0.0,<8.5.1 | 8.5.1 |
| tinymcenpm | <=5.10.9 | Not reported |
| TinyMCEnuget | <5.11.1 | Not reported |
| TinyMCEnuget | >=6.0.0,<7.9.3 | 7.9.3 |
| TinyMCEnuget | >=8.0.0,<8.5.1 | 8.5.1 |
| TinyMCEnuget | <=5.10.9 | Not reported |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard