CVE-2025-14284
Versions of the package @tiptap/extension-link before 2.10.4 are vulnerable to Cross-site Scripting (XSS) due to unsanitized user input allowed in setting or toggling links. An attacker can execute arbitrary JavaScript code in the context of the application by injecting a javascript: URL payload into these attributes, which is then triggered either by user interaction.
Published:Dec 9, 2025
Last Modified:Dec 31, 2025
EPS:Dec 9, 2025
EPSS Score:0.00031
CVSS Score:6.1
Affected Products
Vendor
Product
Action
Vendor
Tiptap
Product
Tiptap
Tiptap
Tiptap
Vendor
Tiptap
Product
Tiptap\/extension-link
Tiptap
Tiptap\/extension-link
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
