Update to ckeditor 45.2.2 (once available)

Created on 3 September 2025, about 1 month ago

Problem/Motivation

https://github.com/ckeditor/ckeditor5/releases/tag/v46.0.3 has been released, fixing an XSS vulnerability.

From reading the release notes, it looks as if Drupal core is not directly vulnerable - we don't enable the HTML Embed plugin in core, and we also don't use ViewRawElement as far as I can tell. However, it would be good to get a second (or third) set of eyes to confirm this is really the case.

Drupal 11.x/11.2/10.6/10.5 are all on 45.2.1, so we need to update to 45.2.2 once this is available.

Steps to reproduce

Proposed resolution

Remaining tasks

User interface changes

Introduced terminology

API changes

Data model changes

Release notes snippet

📌 Task
Status

Active

Version

11.0 🔥

Component

ckeditor5.module

Created by

🇬🇧United Kingdom catch

Live updates comments and jobs are added and updated live.
  • Security improvements

    It makes Drupal less vulnerable to abuse or misuse. Note, this is the preferred tag, though the Security tag has a large body of issues tagged to it. Do NOT publicly disclose security vulnerabilities; contact the security team instead. Anyone (whether security team or not) can apply this tag to security improvements that do not directly present a vulnerability e.g. hardening an API to add filtering to reduce a common mistake in contributed modules.

Sign in to follow issues

Comments & Activities

Production build 0.71.5 2024