CVE-2025-14284: Tiptap Tiptap/extension-Link
Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.
Versions of the package @tiptap/extension-link before 2.10.4 are vulnerable to Cross-site Scripting (XSS) due to unsanitized user input allowed in setting or toggling links. An attacker can execute arbitrary JavaScript code in the context of the application by injecting a javascript: URL payload into these attributes, which is then triggered either by user interaction.
Affected products
- Tiptap Tiptap/extension-Link: before 2.10.4 (fixed in 2.10.4)
Published 2025-12-09. Last modified 2026-06-17.