Junglewise Threat Intelligence

CVE-2025-15056: Slab Quill XSS in HTML export feature

CVE-2025-15056 · Severity: medium · CVSS 6.1 · Published 2026-01-13

Technologies: Slab Quill. Vendors: npm.

Executive brief

Quill is a popular web-based text editor used to provide rich text editing capabilities in applications. A security flaw in its HTML export feature allows an attacker to inject malicious scripts into content. If a user views or processes this exported content, the script could execute in their browser, potentially leading to unauthorized actions or data theft.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in Quill version 2.0.3 due to improper neutralization of input during web page generation (CWE-79) within the HTML export functionality. The root cause is a lack of sufficient data validation when the editor constructs HTML output from user-influenced content. An attacker can exploit this by crafting malicious input that, when exported and subsequently rendered in a victim's browser, executes arbitrary JavaScript. This attack requires user interaction (viewing the exported content) and can lead to a compromise of the integrity and confidentiality of the user's session. As of the advisory date, no patched version has been identified.

Affected products

  • slab quill 2.0.3

Timeline

  • 2026-01-13: disclosed: Vulnerability disclosed and CVE-2025-15056 assigned.
  • 2026-01-13: advisory: GitHub Advisory GHSA-v3m3-f69x-jf25 published.

References

Related threats