OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-104847: ProseMirror has a XSS vulnerability in prosemirror-view's paste handling

GitHub Advisories · officialPublished Oct 5, 2026Risk 37/100

### Impact When a user pastes attacker-provided HTML into a ProseMirror editor component, this can cause attacker-controlled JavaScript code to run in the browser window containing the editor. ### Patches Version 1.42.3 adds validation that prevents this attack. ### Workarounds No known workarounds.

Upgrade affected packages to a patched version: prosemirror-view 1.42.3.

Vendor
Not specified
Product
prosemirror-view
Exploitation
none known
Evidence
official

This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source