QID 982962
QID 982962: Nodejs (npm) Security Update for @ckeditor/ckeditor5-markdown-gfm (GHSA-hgmg-hhc8-g5wr)
Security update has been released for @ckeditor/ckeditor5-markdown-gfm to fix the vulnerability.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
A regular expression denial of service (ReDoS) vulnerability has been discovered in the CKEditor 5 Markdown plugin code. The vulnerability allowed to abuse a link recognition regular expression, which could cause a significant performance drop resulting in a browser tab freeze. It affects all users using the CKEditor 5 Markdown plugin at version <= 24.0.0.
Solution
The problem has been recognized and patched. The fix will be available in version 25.0.0.Workaround:
The user can work around the issue by:
- Upgrading CKEditor 5 to version 25.0.0.
- Disabling the Markdown plugin.
The user can work around the issue by:
- Upgrading CKEditor 5 to version 25.0.0.
- Disabling the Markdown plugin.
Vendor References
- GHSA-hgmg-hhc8-g5wr -
github.com/advisories/GHSA-hgmg-hhc8-g5wr
CVEs related to QID 982962
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-hgmg-hhc8-g5wr | @ckeditor/ckeditor5-markdown-gfm |
|