← back
CVE-2021-32855mediumCWE-79

vditor vulnerable to Cross-site Scripting

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.1epss 0.6%
exploitation probability
0.6%top 54% of all CVEs
observed exploitation
nono source reports it
In short

Vditor, a Markdown editor, has a security flaw where malicious code can be executed if someone tricks you into copying and pasting it into the editor. This could allow attackers to steal your data or take control of your session.

Technical detail

Vditor prior to version 3.8.7 is vulnerable to stored/paste-based XSS where unsanitized content from clipboard operations is rendered without proper validation. The attack requires social engineering to convince the user to copy malicious payload into the editor, resulting in arbitrary JavaScript execution in the victim's browser context.

Summary generated and translated by AI from the official description.
Vditor is a browser-side Markdown editor. Versions prior to 3.8.7 are vulnerable to copy-paste cross-site scripting (XSS). For this particular type of XSS, the victim needs to be fooled into copying a malicious payload into the text editor. Version 3.8.7 contains a patch for this issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected products
npm · vditor