Junglewise Threat Intelligence

Duplicate Advisory: ProsemirrorToHtml has a Cross-Site Scripting (XSS) vulnerability through unescaped HTML attribute values

Severity: low · CVSS 3.1 · Published 2025-11-07

Technologies: prosemirror_to_html (RubyGems). Vendors: RubyGems.

Executive brief

Duplicate Advisory: ProsemirrorToHtml has a Cross-Site Scripting (XSS) vulnerability through unescaped HTML attribute values

Affected products

  • RubyGems prosemirror_to_html

Related threats