npm @ckeditor/ckeditor5-upload 44.2.1

latest releases: 0.0.0-nightly-next-20250222.0, 0.0.0-nightly-20250222.0, 0.0.0-nightly-next-20250221.0...
2 days ago

We are happy to announce the release of CKEditor 5 v44.2.1.

During a recent internal audit, we identified a cross-site scripting (XSS) vulnerability in the CKEditor 5 real-time collaboration package (CVE-2025-25299). This vulnerability can lead to unauthorized JavaScript code execution and affects user markers, which represent users' positions within the document.

This vulnerability affects only installations with real-time collaborative editing enabled.

You can read more details in the relevant security advisory and contact us if you have more questions.

Bug fixes

  • comments: Fixed a few scenarios for which creating a new comment thread was impossible (for example, when a selection was made on multiple table cells). This was a regression introduced in v44.2.0.

Other changes

Released packages

Check out the Versioning policy guide for more information.

Released packages (summary)

Other releases:

Don't miss a new ckeditor5-upload release

NewReleases is sending notifications on new releases.