ProseMirror has a XSS vulnerability in prosemirror-view's paste handling
When a user pastes attacker-provided HTML into a ProseMirror editor component, this can cause attacker-controlled JavaScript code to run in the browser window containing the editor.