{"id":"GHSA-x9gp-vjh6-3wv6","summary":"CKEditor 5 cross-site scripting (XSS) vulnerability in the clipboard package","details":"### Impact\nA Cross-Site Scripting (XSS) vulnerability has been discovered in the CKEditor 5 clipboard package. This vulnerability could be triggered by a specific user action, leading to unauthorized JavaScript code execution, if the attacker managed to insert a malicious content into the editor, which might happen with a very specific editor configuration.\n\nThis vulnerability affects **only** installations where the editor configuration meets one of the following criteria:\n- [HTML embed plugin](https://ckeditor.com/docs/ckeditor5/latest/features/html/html-embed.html) is enabled\n- Custom plugin introducing editable element which implements view [`RawElement`](https://ckeditor.com/docs/ckeditor5/latest/api/module_engine_view_rawelement-ViewRawElement.html) is enabled\n\n### Patches\nThe problem has been recognized and patched. The fix will be available in version 46.0.3 (and above), and explicitly in version 45.2.2.\n\n### For more information\nEmail us at [security@cksource.com](mailto:security@cksource.com) if you have any questions or comments about this advisory.","aliases":["CVE-2025-58064"],"modified":"2025-09-04T13:51:52Z","published":"2025-09-03T18:03:20Z","database_specific":{"nvd_published_at":"2025-09-04T10:42:32Z","cwe_ids":["CWE-79"],"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2025-09-03T18:03:20Z"},"references":[{"type":"WEB","url":"https://github.com/ckeditor/ckeditor5/security/advisories/GHSA-x9gp-vjh6-3wv6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-58064"},{"type":"WEB","url":"https://github.com/ckeditor/ckeditor5/commit/b210e90c6cf84e662ef6c7daf93a92355a961bf2"},{"type":"PACKAGE","url":"https://github.com/ckeditor/ckeditor5"}],"affected":[{"package":{"name":"ckeditor5","ecosystem":"npm","purl":"pkg:npm/ckeditor5"},"ranges":[{"type":"SEMVER","events":[{"introduced":"46.0.0"},{"fixed":"46.0.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-x9gp-vjh6-3wv6/GHSA-x9gp-vjh6-3wv6.json"}},{"package":{"name":"@ckeditor/ckeditor5-clipboard","ecosystem":"npm","purl":"pkg:npm/%40ckeditor/ckeditor5-clipboard"},"ranges":[{"type":"SEMVER","events":[{"introduced":"44.2.0"},{"fixed":"45.2.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-x9gp-vjh6-3wv6/GHSA-x9gp-vjh6-3wv6.json"}},{"package":{"name":"ckeditor5","ecosystem":"npm","purl":"pkg:npm/ckeditor5"},"ranges":[{"type":"SEMVER","events":[{"introduced":"44.2.0"},{"fixed":"45.2.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-x9gp-vjh6-3wv6/GHSA-x9gp-vjh6-3wv6.json"}},{"package":{"name":"@ckeditor/ckeditor5-clipboard","ecosystem":"npm","purl":"pkg:npm/%40ckeditor/ckeditor5-clipboard"},"ranges":[{"type":"SEMVER","events":[{"introduced":"46.0.0"},{"fixed":"46.0.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-x9gp-vjh6-3wv6/GHSA-x9gp-vjh6-3wv6.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N"}]}