Executive brief
Quill is a popular web-based text editor used to provide rich text editing capabilities in applications. A security flaw in its HTML export feature allows an attacker to inject malicious scripts into content. If a user views or processes this exported content, the script could execute in their browser, potentially leading to unauthorized actions or data theft.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in Quill version 2.0.3 due to improper neutralization of input during web page generation (CWE-79) within the HTML export functionality. The root cause is a lack of sufficient data validation when the editor constructs HTML output from user-influenced content. An attacker can exploit this by crafting malicious input that, when exported and subsequently rendered in a victim's browser, executes arbitrary JavaScript. This attack requires user interaction (viewing the exported content) and can lead to a compromise of the integrity and confidentiality of the user's session. As of the advisory date, no patched version has been identified.
Affected products
- slab quill 2.0.3
Timeline
- 2026-01-13: disclosed: Vulnerability disclosed and CVE-2025-15056 assigned.
- 2026-01-13: advisory: GitHub Advisory GHSA-v3m3-f69x-jf25 published.