Cross-site Scripting Vulnerability in react-draft-wysiwyg by Snyk
CVE-2025-3191
5.1MEDIUM
What is CVE-2025-3191?
The react-draft-wysiwyg package is susceptible to a Cross-site Scripting (XSS) attack through the Embedded button feature. An attacker could exploit this vulnerability by injecting malicious scripts, which would be stored in the tag, creating significant security risks for users. It is essential for developers utilizing this package to review their implementations and apply necessary mitigations to protect against potential exploitation.
Affected Version(s)
react-draft-wysiwyg 0
