Junglewise Threat Intelligence

CVE-2025-64501: Cross-Site Scripting (XSS) vulnerability through unescaped HTML attribute values

CVE-2025-64501 · Severity: low · CVSS 3.1 · Published 2025-11-06

Technologies: prosemirror_to_html (RubyGems). Vendors: RubyGems.

Executive brief

Cross-Site Scripting (XSS) vulnerability through unescaped HTML attribute values

Affected products

  • RubyGems prosemirror_to_html

Related threats