Skip to content

Self XSS vulnerability in editor #601

@FlyInk13

Description

@FlyInk13

Describe the bug
There is a self xss vulnerability in the editor

To Reproduce

  1. Open url: data:text/html,<body contenteditable>test1<img src=1 onerror=alert() />test2
  2. Select all content and copy
  3. Paste in editor https://www.blocknotejs.org/

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions