Executive brief
CKEditor 5 is a rich-text editor used to enable users to author content within web applications. A cross-site scripting (XSS) vulnerability in its clipboard component allows attackers to execute arbitrary JavaScript code in a user's browser if they can insert malicious content into the editor through specific configurations (such as when HTML embed or custom RawElement plugins are enabled). This could lead to session hijacking, credential theft, or manipulation of user data.
Technical details
CKEditor 5 contains a reflected XSS vulnerability (CWE-79) in the clipboard package. The vulnerability is triggered when a user performs a specific action (such as pasting or copying) on malicious content inserted into the editor, and only manifests when certain editor configurations are active—specifically when the HTML embed plugin or a custom plugin implementing a RawElement are enabled. Exploitation requires network reachability and user interaction (a specific clipboard action), with no authentication required. An attacker can achieve unauthorized JavaScript execution in the user's browser context. Patches are available: version 46.0.3 and above, and version 45.2.2, fix the issue.
Affected products
- CKEditor CKEditor 5 44.2.0 to 46.0.2
- CKEditor CKEditor 5 Clipboard 44.2.0 to 46.0.2
Timeline
- 2025-09-03: disclosed: Vulnerability published via GHSA-x9gp-vjh6-3wv6
- 2025-09-03: patched: Patches available in CKEditor 5 versions 46.0.3+ and 45.2.2