{"id":"CVE-2025-14284","aliases":["GHSA-vhrc-hgrq-x75r"],"url":"https://o3.security/vulnerability/CVE-2025-14284","summary":"@tiptap/extension-link vulnerable to Cross-site Scripting (XSS)","details":"Versions of the package @tiptap/extension-link before 2.10.4 are vulnerable to Cross-site Scripting (XSS) due to unsanitized user input allowed in setting or toggling links. An attacker can execute arbitrary JavaScript code in the context of the application by injecting a javascript: URL payload into these attributes, which is then triggered either by user interaction.","published":"2025-12-09T05:00:03.409Z","modified":"2026-07-15T01:48:55.327330915Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@tiptap/extension-link","fixedVersion":"2.10.4"}],"fix":{"url":"https://github.com/ueberdosis/tiptap/commit/1c2fefe3d61ab1c8fbaa6d6b597251e1b6d9aaed","label":"ueberdosis/tiptap@1c2fefe"},"references":[{"type":"WEB","url":"https://gist.github.com/th4s1s/3d1b6cd3e7257b14947242f712ec6e1f"},{"type":"WEB","url":"https://github.com/ueberdosis/tiptap/releases/tag/v2.10.4"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-JS-TIPTAPEXTENSIONLINK-14222197"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/14xxx/CVE-2025-14284.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-14284"},{"type":"FIX","url":"https://github.com/ueberdosis/tiptap/commit/1c2fefe3d61ab1c8fbaa6d6b597251e1b6d9aaed"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:48:55.327330915Z"}}