I noticed this while running bun audit:dependencies
These are for @tiptap/core. Both are fixed in the latest, 3.31.3.
react-native-enriched-html@1.1.1 | 3.27.1 | Tiptap: Quadratic ReDoS in block and inline Markdown attribute parsing
| HIGH | Affected range: >=3.7.0 <3.30.5
| | https://github.com/advisories/GHSA-j95f-988m-3j2f
+-----------+-----------------------------------------------------------------
| 3.27.1 | Tiptap: mergeAttributes() turns an own __proto__ key into
| MODERATE | inherited executable DOM attributes
| | Affected range: >=2.0.0-alpha.0 <3.30.4
| | https://github.com/advisories/GHSA-cp6q-959q-f8rh
And while I'm here, DOMPurify also has issues that are fixed in latest.
react-native-enriched-html@1.1.1 | 3.4.11 | DOMPurify: IN_PLACE hook removal leaves a detached subtree
| MODERATE | executable, causing XSS
| | Affected range: <=3.4.12
| | https://github.com/advisories/GHSA-55q2-fjhq-7xh7
+-----------+-----------------------------------------------------------------
| 3.4.11 | DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses
| LOW | `afterSanitizeElements` for allowed custom elements.
| | Affected range: <=3.4.11
| | https://github.com/advisories/GHSA-c2j3-45gr-mqc4
I noticed this while running
bun audit:dependenciesThese are for
@tiptap/core. Both are fixed in the latest,3.31.3.And while I'm here,
DOMPurifyalso has issues that are fixed in latest.