A security researcher—Pedro Paniago (drop)—has brought a vulnerability in pre-1.42.3 versions of prosemirror-view to my attention. The issue allows an attacker that is able to get the user to paste HTML crafted by them into a ProseMirror editor to run arbitrary JavaScript code in the editor’s browser window. I recommend upgrading to the new version as soon as possible.
I should make clear, this is no obvious exploit—it involves a very clever very obscure trick. As far as I’m aware only me and the researcher that found the issue know that trick at this point and it hasn’t been seen in the wild. But with language models being able to poke at these things and stumble upon even the most obscure exploits, there’s no telling how long it’ll stay that way.