zenoamaro / react-quill

A Quill component for React.
https://zenoamaro.github.io/react-quill
MIT License
6.79k stars 926 forks source link

Cross-site Scripting in Quill #1011

Open Alex-Inems opened 1 month ago

Alex-Inems commented 1 month ago

Vulnerability Issues with Quill and React-Quill

Description I'm experiencing security vulnerabilities reported by npm audit related to the quill library. The vulnerabilities include Cross-site Scripting (XSS) and others as detailed in the reports.

Current Versions

pruchay commented 1 month ago

Unfortunately, I think this issue will be not fixed. Looks like this library is abandoned. I installed the forked library with an updated quill - everything works fine and now I don't have vulnerabilities. You can read about that forked library here Update Quill Dependency to ^2.0.0.