Junglewise Threat Intelligence

CVE-2024-38356: PYSEC-2026-1301 - TinyMCE Cross-Site Scripting (XSS) vulnerability using noneditable_regexp option

CVE-2024-38356 · Severity: low · CVSS 3.1 · Published 2026-07-07

Technologies: Tinymce, django-tinymce (PyPI). Vendors: PyPI.

Executive brief

TinyMCE is a popular rich-text editor used in websites and applications to allow users to create and format content. An attacker can inject malicious code through specially crafted HTML attributes when the noneditable_regexp option is enabled, allowing the code to execute when content is extracted from the editor. This could lead to account compromise, session hijacking, or unauthorized actions performed on behalf of the user.

Technical details

This is a cross-site scripting (XSS) vulnerability (CWE-79) in TinyMCE's content extraction code when the noneditable_regexp option is configured. The vulnerability exists because the editor fails to properly validate that HTML attribute content matches the configured regular expression before processing it, allowing malicious payloads to bypass sanitization. Attack requires network access and user interaction (a user must extract content from the editor containing the malicious payload). An attacker can execute arbitrary JavaScript in the context of the affected user's session. The vulnerability has been patched in TinyMCE 7.2.0, 6.8.4, and 5.11.0 LTS by adding proper attribute validation against the configured regular expression.

Affected products

  • Tiny TinyMCE <5.11.0, 6.0.0-6.8.3, 7.0.0-7.1.2
  • Tiny TinyMCE 5.x before 5.11.0 LTS

Timeline

  • 2024-06-19: disclosed: Vulnerability published
  • 2024-06-19: patched: TinyMCE 7.2.0, 6.8.4, and 5.11.0 LTS patched

References

Related threats