This repository was archived by the owner on Nov 6, 2025. It is now read-only.
Commit be1562e
committed
fix: Tinymce allows potentially unsafe embeds
This sets `convert_unsafe_embeds` to true to act as a workaround for CVE-2024-29881 seeing that we cannot upgrade to tinymce 7 at the moment. The only difference from TinyMCE 6 to 7 in this regard is that this option is set to true and is the official workaround.
Fixes https://github.com/umbraco/Umbraco.CMS.Backoffice/security/dependabot/441 parent 6366776 commit be1562e
File tree
1 file changed
+1
-0
lines changed- src/packages/tiny-mce/components/input-tiny-mce
1 file changed
+1
-0
lines changedLines changed: 1 addition & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
243 | 243 | | |
244 | 244 | | |
245 | 245 | | |
| 246 | + | |
246 | 247 | | |
247 | 248 | | |
248 | 249 | | |
| |||
0 commit comments