This repository was archived by the owner on Jun 3, 2026. It is now read-only.
⬆️ Update dependency @tiptap/extension-link to v2.10.4 [SECURITY]#2337
Open
renovate[bot] wants to merge 1 commit into
Open
⬆️ Update dependency @tiptap/extension-link to v2.10.4 [SECURITY]#2337renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
Coverage Report
File CoverageNo changed files found. |
db85415 to
bb5dc5c
Compare
bb5dc5c to
0ad5c2d
Compare
0ad5c2d to
0059789
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
2.1.12→2.10.4@tiptap/extension-link vulnerable to Cross-site Scripting (XSS)
CVE-2025-14284 / GHSA-vhrc-hgrq-x75r
More information
Details
Versions of the package @tiptap/extension-link before 2.10.4 are vulnerable to Cross-site Scripting (XSS) due to unsanitized user input allowed in setting or toggling links. An attacker can execute arbitrary JavaScript code in the context of the application by injecting a javascript: URL payload into these attributes, which is then triggered either by user interaction.
Severity
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:PReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
ueberdosis/tiptap (@tiptap/extension-link)
v2.10.4Compare Source
What's Changed
Full Changelog: ueberdosis/tiptap@v2.10.3...v2.10.4
v2.10.3Compare Source
What's Changed
contentlarger than limit should truncate #5851 (#5862)Full Changelog: ueberdosis/tiptap@v2.10.2...v2.10.3
v2.10.2Compare Source
What's Changed
Full Changelog: ueberdosis/tiptap@v2.10.1...v2.10.2
v2.10.1Compare Source
What's Changed
Full Changelog: ueberdosis/tiptap@v2.10.0...v2.10.1
v2.10.0Compare Source
What's Changed
addOptions,addStorageto have an optional parent #5768 by @nperez0111 in #5770onceto EventEmitters by @nperez0111 in #5818BubbleMenuby @felixgabler in #5842New Contributors
Full Changelog: ueberdosis/tiptap@v2.9.1...v2.10.0
v2.9.1Compare Source
What's Changed
Full Changelog: ueberdosis/tiptap@v2.9.0...v2.9.1
v2.9.0Compare Source
What's Changed
New Contributors
Full Changelog: ueberdosis/tiptap@v2.8.0...v2.9.0
v2.8.0Compare Source
#5669
What's Changed
CharacterCountextension. by @ho991217 in #5674New Contributors
Full Changelog: ueberdosis/tiptap@v2.7.4...v2.8.0
v2.7.4Compare Source
#5667
What's Changed
New Contributors
Full Changelog: ueberdosis/tiptap@v2.7.3...v2.7.4
v2.7.3Compare Source
#5652 (comment)
What's Changed
New Contributors
Full Changelog: ueberdosis/tiptap@v2.7.2...v2.7.3
v2.7.2Compare Source
#5631
What's Changed
Full Changelog: ueberdosis/tiptap@v2.7.1...v2.7.2
v2.7.1Compare Source
#5627
What's Changed
New Contributors
Full Changelog: ueberdosis/tiptap@v2.7.0...v2.7.1
v2.7.0Compare Source
#5511
What's Changed
preventClearDocumentmeta + makes it easier to disable specific core plugins. by @AlansCodeLog in #5514Esc(#4380) by @rfgamaral in #5544New Contributors
Full Changelog: ueberdosis/tiptap@v2.6.6...v2.7.0
v2.6.6Compare Source
#5537
What's Changed
Esc(#4380) by @rfgamaral in #5544New Contributors
Full Changelog: ueberdosis/tiptap@v2.6.5...v2.6.6
v2.6.5Compare Source
#5532
What's Changed
Full Changelog: ueberdosis/tiptap@v2.6.4...v2.6.5
v2.6.4Compare Source
#5497
What's Changed
Full Changelog: ueberdosis/tiptap@v2.6.3...v2.6.4
v2.6.3Compare Source
#5484
What's Changed
img.ProseMirror-separator0px by @tjenkinson in #4646New Contributors
Full Changelog: ueberdosis/tiptap@v2.6.2...v2.6.3
v2.6.2Compare Source
What's Changed
Full Changelog: ueberdosis/tiptap@v2.6.1...v2.6.2
v2.6.1Compare Source
#5480
What's Changed
Full Changelog: ueberdosis/tiptap@v2.6.0...v2.6.1
v2.6.0Compare Source
#5458
What's Changed
hrefto number or boolean by @yurtsiv in #5391New Contributors
Full Changelog: ueberdosis/tiptap@v2.5.9...v2.6.0
v2.5.9Compare Source
What's Changed
<li data-checkedinstead of only when<li data-checked="true"(re-fix of #5366) by @baseballyama in #5426configuremethods (Extension/Mark/Node) by @rfgamaral in #5421isNodeEmptycriteria #5415 by @nperez0111 in #5419useEditoranduseEditorStateto reduce number of instances created while being performant #5432 by @nperez0111 in #5445onFirstRenderby @nperez0111 in #5411defaultLanguageon code-block-lowlight add option tocode-blockby @nperez0111 in #5406New Contributors
Full Changelog: ueberdosis/tiptap@v2.5.8...v2.5.9
v2.5.8Compare Source
Patch Changes
a08bf85]v2.5.7Compare Source
Patch Changes
b012471]cc3497e]v2.5.6Compare Source
Patch Changes
c0e5398: Links were opening twive when the editor was not editable and openOnclick was true, now openOnClick setting will check if it is editable before trying to open programmatically resolves #4877b5c1b32]618bca9]35682d1]2104f0f]v2.5.5Compare Source
Patch Changes
4cca382]3b67e8a]v2.5.4Compare Source
Patch Changes
dd7f9ac: There was an issue with the cjs bundling of packages and default exports, now we resolve default exports in legacy compatible waydd7f9ac]v2.5.3Compare Source
Patch Changes
a473826: Make openOnClick backwards compatible with previouswhenNotEditablevalue, this is now the default and is deprecatedv2.5.2Compare Source
Patch Changes
07f4c03]v2.5.1Compare Source
Patch Changes
v2.5.0Compare Source
Patch Changes
fb45149]fb45149]fb45149]fb45149]v2.4.0Compare Source
Features
2.3.2 (2024-05-08)
Note: Version bump only for package @tiptap/extension-link
2.3.1 (2024-04-30)
Note: Version bump only for package @tiptap/extension-link
v2.3.2Compare Source
Note: Version bump only for package @tiptap/extension-link
v2.3.1Compare Source
Note: Version bump only for package @tiptap/extension-link
v2.3.0Compare Source
Note: Version bump only for package @tiptap/extension-link
2.2.6 (2024-04-06)
Note: Version bump only for package @tiptap/extension-link
2.2.5 (2024-04-05)
Bug Fixes
2.2.4 (2024-02-23)
Note: Version bump only for package @tiptap/extension-link
2.2.3 (2024-02-15)
Note: Version bump only for package @tiptap/extension-link
2.2.2 (2024-02-07)
Note: Version bump only for package @tiptap/extension-link
2.2.1 (2024-01-31)
Note: Version bump only for package @tiptap/extension-link
v2.2.6Compare Source
Note: Version bump only for package @tiptap/extension-link
v2.2.5Compare Source
Bug Fixes
v2.2.4Compare Source
Note: Version bump only for package @tiptap/extension-link
v2.2.3Compare Source
Note: Version bump only for package @tiptap/extension-link
v2.2.2Compare Source
Note: Version bump only for package @tiptap/extension-link
v2.2.1Compare Source
Note: Version bump only for package @tiptap/extension-link
v2.2.0Compare Source
v2.1.16Compare Source
Note: Version bump only for package [@tiptap/extension-link](https://redirect.github.com/tiptap/extension
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.