Total vulnerabilities in the database
A regex denial of service (ReDoS) vulnerability was discovered in a dependency of the codesample
plugin. The vulnerability allowed poorly formed ruby code samples to lock up the browser while performing syntax highlighting. This impacts users of the codesample
plugin using TinyMCE 5.5.1 or lower.
This vulnerability has been patched in TinyMCE 5.6.0 by upgrading to a version of the dependency without the vulnerability.
To work around this vulnerability, either:
codesample
pluginTiny Technologies would like to thank Erik Krogh Kristensen at GitHub for discovering this vulnerability.
https://www.tiny.cloud/docs/release-notes/release-notes56/#securityfixes
If you have any questions or comments about this advisory: