Medium severity5.4NVD Advisory· Published Oct 1, 2020· Updated Jun 17, 2026
CVE-2019-20903
CVE-2019-20903
Description
The hyperlinks functionality in atlaskit/editor-core in before version 113.1.5 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in link targets.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@atlaskit/editor-corenpm | >= 0 | — |
Affected products
3cpe:2.3:a:atlassian:editor-core:*:*:*:*:*:node.js:*:*+ 1 more
- cpe:2.3:a:atlassian:editor-core:*:*:*:*:*:node.js:*:*range: <113.1.5
- (no CPE)range: unspecified
Patches
Vulnerability mechanics
References
7- atlaskit.atlassian.com/packages/editor/editor-core/changelog/113.1.5nvdRelease NotesVendor AdvisoryWEB
- confluence.atlassian.com/pages/viewpage.actionnvdVendor AdvisoryWEB
- github.com/advisories/GHSA-p5ch-w78f-xh44ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-20903ghsaADVISORY
- bitbucket.org/atlassian/atlaskit-mk-2/commits/ca88f616e4ghsaWEB
- www.npmjs.com/package/@atlaskit/editor-coreghsaWEB
- www.npmjs.com/package/%40atlaskit/editor-corenvd
News mentions
0No linked articles in our index yet.