QID 982962

QID 982962: Nodejs (npm) Security Update for @ckeditor/ckeditor5-markdown-gfm (GHSA-hgmg-hhc8-g5wr)

Security update has been released for @ckeditor/ckeditor5-markdown-gfm to fix the vulnerability.

Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.

A regular expression denial of service (ReDoS) vulnerability has been discovered in the CKEditor 5 Markdown plugin code. The vulnerability allowed to abuse a link recognition regular expression, which could cause a significant performance drop resulting in a browser tab freeze. It affects all users using the CKEditor 5 Markdown plugin at version <= 24.0.0.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution
    The problem has been recognized and patched. The fix will be available in version 25.0.0.Workaround:
    The user can work around the issue by:
    - Upgrading CKEditor 5 to version 25.0.0.
    - Disabling the Markdown plugin.
    Vendor References

    CVEs related to QID 982962

    Software Advisories
    Advisory ID Software Component Link
    GHSA-hgmg-hhc8-g5wr @ckeditor/ckeditor5-markdown-gfm URL Logo github.com/advisories/GHSA-hgmg-hhc8-g5wr