netcarver/textile security: XSS vulnerability

Created on 8 January 2025, 15 days ago

Problem/Motivation

High security vulnerability.

Steps to reproduce

❯ composer audit

Found 1 security vulnerability advisory affecting 1 package:
+-------------------+----------------------------------------------------------------------------------+
| Package           | netcarver/textile                                                                |
| Severity          | high                                                                             |
| CVE               | NO CVE                                                                           |
| Title             | PHP-Textile has persistent XSS vulnerability in image link handling              |
| URL               | https://github.com/advisories/GHSA-95m2-chm4-mq7m                                |
| Affected versions | <=4.1.2                                                                          |
| Reported at       | 2025-01-07T17:11:02+00:00                                                        |
| Advisory ID       | PKSA-q7hq-sbtp-vntg                                                              |
+-------------------+----------------------------------------------------------------------------------+

❯ composer why netcarver/textile

drupal/paragraphs_paste 2.0.0-beta6 requires netcarver/textile (^3.7) 

Proposed resolution

Test with 4.1.3 or wait for 3.x release with back ported fix from 4.1.3.

Remaining tasks

  • Testing with 4.1.3.
  • Cut a new release with updated dependency.
πŸ“Œ Task
Status

Active

Version

2.0

Component

Miscellaneous

Created by

πŸ‡ΊπŸ‡ΈUnited States utcwebdev

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Merge Requests

Comments & Activities

Production build 0.71.5 2024