CVE-2025-3191: React Draft Wysiwyg Cross-Site Scripting (XSS) via the Embedded Button
All versions of the package react-draft-wysiwyg are vulnerable to Cross-site Scripting (XSS) via the Embedded button which will then result in saving the payload in the tag.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-3191 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →