Vulnerability Description
All versions of the package react-draft-wysiwyg are vulnerable to Cross-site Scripting (XSS) via the Embedded button which will then result in saving the payload in the <iframe> tag.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://gist.github.com/th4s1s/175ae4b2632096059b42377dd6c49d47
- https://security.snyk.io/vuln/SNYK-JS-REACTDRAFTWYSIWYG-8515884
- https://gist.github.com/th4s1s/175ae4b2632096059b42377dd6c49d47
FAQ
What is CVE-2025-3191?
CVE-2025-3191 is a vulnerability with a CVSS score of 6.1 (MEDIUM). All versions of the package react-draft-wysiwyg are vulnerable to Cross-site Scripting (XSS) via the Embedded button which will then result in saving the payload in the <iframe> tag.
How severe is CVE-2025-3191?
CVE-2025-3191 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-3191?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.