Back to Database
Status published
Unknown
CVE-2023-30792
Anchor tag hrefs in Lexical prior to v0.10.0 would render...
Vulnerability Description
Anchor tag hrefs in Lexical prior to v0.10.0 would render javascript: URLs, allowing for cross-site scripting on link clicks in cases where input was being parsed from untrusted sources.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-30792
Credits & Attribution
No credits recorded in the NVD database.
More from Meta Platforms, Inc
View All →CVE-2025-55178
Llama Stack prior to version v0.2.20 accepted unverified parameters in...
Unknown
0
CVE-2025-54952
An integer overflow vulnerability in the loading of ExecuTorch models...
Unknown
0
CVE-2025-54951
A group of related buffer overflow vulnerabilities in the loading...
Unknown
0
CVE-2025-54950
An out-of-bounds access vulnerability in the loading of ExecuTorch models...
Unknown
0
CVE-2025-54949
A heap buffer overflow vulnerability in the loading of ExecuTorch...
Unknown
0
Affected Vendor
Meta Platforms, Inc
View all reports →Affected Software
Lexical
Vulnerable Versions:
0.0.0
Timeline
Official Publish:
April 29th, 2023
Last Modified:
January 30th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
No vector data available
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.