Executive brief
CKEditor 5 is a popular JavaScript-based rich text editor used to create and edit content on websites. A cross-site scripting vulnerability in the clipboard handling component allows attackers to execute malicious JavaScript in users' browsers if specific editor plugins are enabled (Block Toolbar combined with General HTML Support or HTML Embed). This could lead to session hijacking, credential theft, or defacement of user content.
Technical details
The vulnerability is a cross-site scripting (XSS) flaw (CWE-79) in CKEditor 5's clipboard package that requires user interaction and a specific editor configuration combining the Block Toolbar plugin with either General HTML Support (permitting unsafe markup) or the HTML Embed plugin. An attacker must insert malicious content into the editor, which is then executed as JavaScript in the user's browser. The vulnerability affects versions 40.0.0 through 43.1.0 and has been patched in versions 43.1.1 and 41.3.2. No exploitation in the wild has been reported.
Affected products
- CKSource CKEditor 5 40.0.0 to 43.1.0
- CKSource ckeditor5-clipboard 40.0.0 to 43.1.0
Timeline
- 2024-09-25: disclosed: GHSA-rgg8-g5x8-wr9v published; CVE-2024-45613 assigned
- 2024-09-25: patched: Fix available in versions 43.1.1 and 41.3.2