-
-
Notifications
You must be signed in to change notification settings - Fork 623
Closed
Labels
bugSomething isn't workingSomething isn't working
Description
Describe the bug
There is a self xss vulnerability in the editor
To Reproduce
- Open url:
data:text/html,<body contenteditable>test1<img src=1 onerror=alert() />test2
- Select all content and copy
- Paste in editor https://www.blocknotejs.org/
Metadata
Metadata
Assignees
Labels
bugSomething isn't workingSomething isn't working