HTML content that get pasted into a document is not sanitized. For the security point of view there is no known exploitation path but it can confused users because the copy/pasted content might be different once it is pasted.
Assisted-by: Discovery assisted by Vercel Deepsec using claude-opus-4.8 and claude-sonnet-5.
Internal references: tuleap-deepsec-xss-999e8c222e.