Skip to content

tinymce 4.x has a vulnerability, could mosaico be distributed with 5.x by default? #685

Answered by bago
BarbieroDB1 asked this question in Q&A
Discussion options

You must be logged in to vote
  1. "Are there any plans of updating mosaico to ship with tinyMCE 5 by default?": no plans, as Tinymce versions are full of bugs and we found 4.9.11 is stable enough (and we added a lot of version specific workarounds and testing hours for this version);
  2. "Or maybe a separate branch?": we accept contributions;
  3. "Is current mosaico even vulnerable to GHSA-gg8r-xjwq-4w92 due to the underlying tinyMCE?": AFAIK no as the CVE is about "alerts" by plugins like the image plugin and we don't use them.

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by BarbieroDB1
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants
Converted from issue

This discussion was converted from issue #684 on April 02, 2023 14:43.