MajorCritical vulnerability
CVE-2026-104847: ProseMirror has a XSS vulnerability in prosemirror-view's paste handling
GitHub Advisories · officialPublished Oct 5, 2026Risk 37/100
### Impact When a user pastes attacker-provided HTML into a ProseMirror editor component, this can cause attacker-controlled JavaScript code to run in the browser window containing the editor. ### Patches Version 1.42.3 adds validation that prevents this attack. ### Workarounds No known workarounds.
Recommended action
Recommended action
Upgrade affected packages to a patched version: prosemirror-view 1.42.3.
Technical details
- Vendor
- Not specified
- Product
- prosemirror-view
- Exploitation
- none known
- Evidence
- official
Evidence and sources
This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source