[GHSA-cp6q-959q-f8rh] Tiptap: mergeAttributes() turns an own __proto__ key into inherited executable DOM attributes - #9375
Conversation
|
Hi there @bdbch! A community member has suggested an improvement to your security advisory. If approved, this change will affect the global advisory listed at github.com/advisories. It will not affect the version listed in your project repository. This change will be reviewed by our Security Curation Team. If you have thoughts or feedback, please share them in a comment here! If this PR has already been closed, you can start a new community contribution for this advisory |
There was a problem hiding this comment.
🟡 Changes recommended
The advisory timestamp and remediation narrative remain inconsistent with the added fixed releases.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Pull request overview
Updates the Tiptap security advisory to reflect the v2 backport.
Changes:
- Splits affected v2 and v3 ranges.
- Adds fixed versions and v2 backport references.
- Adjusts the modification timestamp.
The timestamp must reflect the actual update time, and the narrative must identify 2.27.3 and 3.30.4 as fixed releases.
File summaries
| File | Description |
|---|---|
advisories/github-reviewed/2026/09/GHSA-cp6q-959q-f8rh/GHSA-cp6q-959q-f8rh.json |
Updates affected ranges, fixes, references, and metadata; requires timestamp and narrative corrections. |
Review details
- Files reviewed: 1/1 changed files
- Comments generated: 2
- Review effort level: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| "schema_version": "1.4.0", | ||
| "id": "GHSA-cp6q-959q-f8rh", | ||
| "modified": "2026-09-02T14:44:39Z", | ||
| "modified": "2026-09-02T14:44:40Z", |
There was a problem hiding this comment.
This timestamp is generated by the GitHub process, not me
|
Hi there @bdbch! A community member has suggested an improvement to your security advisory. If approved, this change will affect the global advisory listed at github.com/advisories. It will not affect the version listed in your project repository. This change will be reviewed by our Security Curation Team. If you have thoughts or feedback, please share them in a comment here! If this PR has already been closed, you can start a new community contribution for this advisory |
|
Hi there @bdbch! A community member has suggested an improvement to your security advisory. If approved, this change will affect the global advisory listed at github.com/advisories. It will not affect the version listed in your project repository. This change will be reviewed by our Security Curation Team. If you have thoughts or feedback, please share them in a comment here! If this PR has already been closed, you can start a new community contribution for this advisory |
Updates
Comments
Update to reflect v2 backport