VYPR

prosemirror-view

by ProseMirror

CVEs (1)

  • CVE-2026-104847HigOct 2, 2026
    risk 0.48cvss —epss —

    ProseMirror's view component renders and manages the editable browser interface for ProseMirror documents. Prior to 1.42.3, prosemirror-view paste handling accepts attacker-provided HTML whose clipboard slice context contains attributes that are not passed through schema…