Vulnerability Description
Versions of the package @excalidraw/excalidraw from 0.0.0 are vulnerable to Cross-site Scripting (XSS) via embedded links in whiteboard objects due to improper input sanitization.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Excalidraw | Excalidraw | All versions |
Related Weaknesses (CWE)
References
- https://github.com/excalidraw/excalidraw/commit/b33fa6d6f64d27adc3a47b25c0aa5571Patch
- https://github.com/excalidraw/excalidraw/pull/6728Issue Tracking
- https://security.snyk.io/vuln/SNYK-JS-EXCALIDRAWEXCALIDRAW-5841658Third Party Advisory
- https://github.com/excalidraw/excalidraw/commit/b33fa6d6f64d27adc3a47b25c0aa5571Patch
- https://github.com/excalidraw/excalidraw/pull/6728Issue Tracking
- https://security.snyk.io/vuln/SNYK-JS-EXCALIDRAWEXCALIDRAW-5841658Third Party Advisory
FAQ
What is CVE-2023-26140?
CVE-2023-26140 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Versions of the package @excalidraw/excalidraw from 0.0.0 are vulnerable to Cross-site Scripting (XSS) via embedded links in whiteboard objects due to improper input sanitization.
How severe is CVE-2023-26140?
CVE-2023-26140 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-26140?
Check the references section above for vendor advisories and patch information. Affected products include: Excalidraw Excalidraw.