{"id":"GHSA-j3mm-wmfm-mwvh","summary":"Cross-site scripting (XSS) in the CKEditor 5 real-time collaboration package","details":"### Impact\nDuring a recent internal audit, we identified a Cross-Site Scripting (XSS) vulnerability in the CKEditor 5 real-time collaboration package. This vulnerability can lead to unauthorized JavaScript code execution and affects user markers, which represent users' positions within the document.\n\nThis vulnerability affects only installations with [Real-time collaborative editing](https://ckeditor.com/docs/ckeditor5/latest/features/collaboration/real-time-collaboration/real-time-collaboration.html) enabled.\n\n### Patches\nThe problem has been recognized and patched. The fix will be available in version 44.2.1 (and above).\n\n### For more information\nEmail us at [security@cksource.com](mailto:security@cksource.com) if you have any questions or comments about this advisory.","aliases":["CVE-2025-25299"],"modified":"2025-02-20T22:53:45Z","published":"2025-02-20T20:16:31Z","database_specific":{"nvd_published_at":"2025-02-20T20:15:46Z","cwe_ids":["CWE-79","CWE-80"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2025-02-20T20:16:31Z"},"references":[{"type":"WEB","url":"https://github.com/ckeditor/ckeditor5/security/advisories/GHSA-j3mm-wmfm-mwvh"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-25299"},{"type":"WEB","url":"https://ckeditor.com/docs/ckeditor5/latest/features/collaboration/real-time-collaboration/real-time-collaboration.html"},{"type":"WEB","url":"https://ckeditor.com/docs/ckeditor5/latest/features/collaboration/real-time-collaboration/real-time-collaboration.html?docId=ee1dca024c9b4e44aef039f99ebe6c664"},{"type":"PACKAGE","url":"https://github.com/ckeditor/ckeditor5"},{"type":"WEB","url":"https://github.com/ckeditor/ckeditor5/releases/tag/v44.2.1"}],"affected":[{"package":{"name":"@ckeditor/ckeditor5-real-time-collaboration","ecosystem":"npm","purl":"pkg:npm/%40ckeditor/ckeditor5-real-time-collaboration"},"ranges":[{"type":"SEMVER","events":[{"introduced":"41.3.0"},{"fixed":"44.2.1"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 44.2.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/02/GHSA-j3mm-wmfm-mwvh/GHSA-j3mm-wmfm-mwvh.json"}},{"package":{"name":"ckeditor5-premium-features","ecosystem":"npm","purl":"pkg:npm/ckeditor5-premium-features"},"ranges":[{"type":"SEMVER","events":[{"introduced":"42.0.0"},{"fixed":"44.2.1"}]}],"database_specific":{"last_known_affected_version_range":"\u003c 44.2.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/02/GHSA-j3mm-wmfm-mwvh/GHSA-j3mm-wmfm-mwvh.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"}]}