---
title: "TinyMCE 7.4.1"
description: "Release notes for TinyMCE 7.4.1"
canonical_url: "https://www.tiny.cloud/docs/tinymce/7/7.4.1-release-notes/"
md_url: "https://www.tiny.cloud/docs/tinymce/7/7.4.1-release-notes/index.md"
version: "7"
last_updated: "2024-10-10T06:26:17Z"
tokens: 529
---
Important This page documents TinyMCE 7. For new projects, Tiny recommends using the latest, most up-to-date version. [See TinyMCE 8 documentation](../../latest/).
# TinyMCE 7.4.1

> **Note:** These are the Tiny Cloud and TinyMCE Enterprise release notes. For information on the latest community version of TinyMCE, see the [TinyMCE Changelog](../changelog/).

## Overview

TinyMCE 7.4.1 was released for TinyMCE Enterprise and Tiny Cloud on Wednesday, October 10 th, 2024.

These release notes provide an overview of the changes for TinyMCE 7.4.1, including:

- [Security fix](#security-fix)

## Security fix

TinyMCE 7.4.1 includes one fix for the following security issue:

### Invalid HTML elements within `SVG` elements were not removed

A [cross-site scripting](https://owasp.org/www-community/attacks/xss/) (XSS) vulnerability was discovered in [DOMPurify](https://www.npmjs.com/package/dompurify) that affects versions of TinyMCE prior to 7.4.1 release. The issue was a result of DOMPurify allowing some bypassing which lead to improper sanitization of invalid HTML elements within XML contexts, exploiting parsing inconsistencies between XML and HTML.

### Affected Versions

DOMPurify versions prior to `<3.1.7`

### Vulnerabilities

- **Invalid HTML Elements in SVG** ([CVE-2024-45801](https://www.cve.org/CVERecord?id=CVE-2024-45801)): Allowed invalid HTML elements within `SVG` to bypass sanitization.
- **XML Processing Instruction Bypass**: Exploited differences in XML and HTML parsers regarding Processing Instructions, where XML parsed `<?xml-stylesheet ><h1>Hello</h1> ?>` as a single node, allowing `h1` to bypass sanitization.
- **CDATA Section Bypass**: Leveraged differences in CDATA section handling between XML and HTML namespaces, with CDATA treated as bogus comments in HTML, bypassing end token rules for sanitization.

GHSA: [GitHub Advisory](https://github.com/cure53/DOMPurify/security/advisories/GHSA-mmhx-hmjr-r674)

CVE: [CVE-2024-45801](https://www.cve.org/CVERecord?id=CVE-2024-45801)
