Junglewise Threat Intelligence

CVE-2024-29881: TinyMCE cross-site scripting in SVG handling via object or embed elements

CVE-2024-29881 · Severity: low · CVSS 3.1 · Published 2024-03-26

Technologies: tinymce (npm). Vendors: npm.

Executive brief

TinyMCE is a widely used rich-text editor embedded in web applications and content management systems. The vulnerability allows attackers to inject malicious JavaScript through SVG files loaded via object or embed HTML elements, potentially stealing user data or performing unauthorized actions on behalf of users. User interaction is required—the attack occurs when editing content containing a malicious SVG file.

Technical details

The vulnerability is a CWE-79 cross-site scripting (XSS) flaw in TinyMCE's content loading and content inserting code. When a user or attacker-controlled content includes an SVG image referenced via an object or embed HTML element, the SVG content may contain malicious JavaScript that executes within the editor's security context without proper sanitization. The attack requires network access to the editor and user interaction (editing or viewing content). No authentication is required. An attacker can achieve arbitrary JavaScript execution within the editor scope, potentially leading to data exfiltration or unauthorized modifications. The fix was addressed in version 6.8.1 by introducing the convert_unsafe_embeds option, which automatically converts unsafe object and embed elements to safer alternatives (img, video, audio, or iframe based on MIME type). This option is enabled by default in TinyMCE 7.0.0 and later. For versions 6.8.1–6.8.6, users must explicitly enable the option or implement a custom NodeFilter.

Affected products

  • Tiny Technologies TinyMCE < 7.0.0 (all prior versions affected; 6.8.1+ provides workaround via convert_unsafe_embeds option)

Timeline

  • 2024-03-26: disclosed: Advisory GHSA-5359-pvf2-pw78 published
  • 2023-11-21: patched: TinyMCE 6.8.1 introduced convert_unsafe_embeds option (mitigation); fix released in commit bcdea2ad
  • 2024: patched: TinyMCE 7.0.0 released with convert_unsafe_embeds enabled by default (complete fix)

References

Related threats