{"id":"CVE-2025-58064","aliases":["GHSA-x9gp-vjh6-3wv6"],"url":"https://o3.security/vulnerability/CVE-2025-58064","summary":"CKEditor is susceptible to Cross-Site Scripting (XSS) through its clipboard package","details":"### Impact\nA Cross-Site Scripting (XSS) vulnerability has been discovered in the CKEditor 5 clipboard package. This vulnerability could be triggered by a specific user action, leading to unauthorized JavaScript code execution, if the attacker managed to insert a malicious content into the editor, which might happen with a very specific editor configuration.\n\nThis vulnerability affects **only** installations where the editor configuration meets one of the following criteria:\n- [HTML embed plugin](https://ckeditor.com/docs/ckeditor5/latest/features/html/html-embed.html) is enabled\n- Custom plugin introducing editable element which implements view [`RawElement`](https://ckeditor.com/docs/ckeditor5/latest/api/module_engine_view_rawelement-ViewRawElement.html) is enabled\n\n### Patches\nThe problem has been recognized and patched. The fix will be available in version 46.0.3 (and above), and explicitly in version 45.2.2.\n\n### For more information\nEmail us at [security@cksource.com](mailto:security@cksource.com) if you have any questions or comments about this advisory.","published":"2025-09-03T22:02:53.296Z","modified":"2026-08-12T03:51:16.119683213Z","cvss":null,"epss":{"score":0.00417,"percentile":0.34498,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"ckeditor5","fixedVersion":"46.0.3"},{"ecosystem":"npm","name":"@ckeditor/ckeditor5-clipboard","fixedVersion":"45.2.2"},{"ecosystem":"npm","name":"ckeditor5","fixedVersion":"45.2.2"},{"ecosystem":"npm","name":"@ckeditor/ckeditor5-clipboard","fixedVersion":"46.0.3"}],"fix":{"url":"https://github.com/ckeditor/ckeditor5/commit/b210e90c6cf84e662ef6c7daf93a92355a961bf2","label":"ckeditor/ckeditor5@b210e90"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/58xxx/CVE-2025-58064.json"},{"type":"ADVISORY","url":"https://github.com/ckeditor/ckeditor5/security/advisories/GHSA-x9gp-vjh6-3wv6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-58064"},{"type":"FIX","url":"https://github.com/ckeditor/ckeditor5/commit/b210e90c6cf84e662ef6c7daf93a92355a961bf2"},{"type":"PACKAGE","url":"https://github.com/ckeditor/ckeditor5"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:16.119683213Z"}}