Cross-Site Scripting Vulnerability in CKEditor 5 by CKSource
CVE-2025-25299
What is CVE-2025-25299?
A Cross-Site Scripting vulnerability exists within the CKEditor 5 real-time collaboration package, specifically affecting user markers that denote user positions in collaborative documents. This flaw allows for potential unauthorized JavaScript code execution under particular configurations of the editor and token endpoint. It is crucial to note that only installations with real-time collaborative editing enabled are vulnerable. CKSource has addressed this issue in version 44.2.1 and users are strongly encouraged to upgrade to secure their installations.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
ckeditor5 @ckeditor/ckeditor5-real-time-collaboration: >= 41.3.0, < 44.2.1 < @ckeditor/ckeditor5-real-time-collaboration: 41.3.0, 44.2.1
ckeditor5 ckeditor5-premium-features: >= 42.0.0, < 44.2.1 < ckeditor5-premium-features: 42.0.0, 44.2.1
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
