
CVE-2024-40626 – Stored Cross-site Scripting (XSS) vulnerability in Outline editor
https://notcve.org/view.php?id=CVE-2024-40626
16 Jul 2024 — Outline is an open source, collaborative document editor. A type confusion issue was found in ProseMirror’s rendering process that leads to a Stored Cross-Site Scripting (XSS) vulnerability in Outline. An authenticated user can create a document containing a malicious JavaScript payload. When other users view this document, the malicious Javascript can execute in the origin of Outline. Outline includes CSP rules to prevent third-party code execution, however in the case of self-hosting and having your file ... • https://github.com/outline/outline/security/advisories/GHSA-888c-mvg8-v6wh • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •