A Stored Cross-Site Scripting (XSS) vulnerability exists in the rich text editor due to improper sanitization of the srcdoc attribute on
{
"cwe_ids": [
"CWE-79"
],
"github_reviewed": true,
"github_reviewed_at": "2026-09-25T15:02:11Z",
"nvd_published_at": "2026-09-24T19:17:15Z",
"severity": "HIGH"
}