[CKEditor 5] Change ckeditor5 language config propety check to handle null prototype
state:accepted
Hi
CKEditor 5 uses a null-prototype object when the editor configuration is modified using the editor.config.define() function, in order to prevent prototype pollution vulnerabilities.
https://github.com/ckeditor/ckeditor5/blob/master/packages/ckeditor5-utils/src/config.ts#L198
MathType integration uses hasOwnProperty on the language object from the config, which causes an error when that property is defined using editor.config.define(), as the resulting object has a null prototype and does not include the hasOwnProperty method.
关闭于 2025-10-22 1 条评论