Skip to content

DOC-3511: Add CVE IDs and missing credit to 8.5.1 release notes#4145

Merged
kemister85 merged 1 commit into
tinymce/8from
hotfix/8/DOC-3511
May 22, 2026
Merged

DOC-3511: Add CVE IDs and missing credit to 8.5.1 release notes#4145
kemister85 merged 1 commit into
tinymce/8from
hotfix/8/DOC-3511

Conversation

@kemister85
Copy link
Copy Markdown
Contributor

@kemister85 kemister85 commented May 21, 2026

Summary

  • Replace CVE: _pending_ placeholders with assigned CVE IDs
  • Add missing thank you note for Tadi Kadango and Ivan Babenko on GHSA-q742-qvgc-gc2f

CVE IDs

Advisory CVE
GHSA-vg35-5wq7-3x7w (media plugin) CVE-2026-47761
GHSA-v98h-vmpc-fpqv (mce:protected) CVE-2026-47762
GHSA-q742-qvgc-gc2f (data-mce- attributes) CVE-2026-47759

Test plan

  • Verify CVE links resolve to NVD
  • Verify credit note renders on 8.5.1 release notes page

- CVE-2026-47761 for media plugin data-mce-object injection
- CVE-2026-47762 for mce:protected comments bypass
- CVE-2026-47759 for data-mce- prefixed attribute override
- Add thank you note for Tadi Kadango and Ivan Babenko (GHSA-q742-qvgc-gc2f)
Copy link
Copy Markdown
Contributor

@ShiridiGandham ShiridiGandham left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@kemister85 kemister85 merged commit 3aeda76 into tinymce/8 May 22, 2026
5 checks passed
@kemister85 kemister85 deleted the hotfix/8/DOC-3511 branch May 22, 2026 02:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants