๐Ÿ” CVE Alert

CVE-2026-65842

HIGH 8.2

Plate: SSRF with response disclosure in DOCX image embedding

CVSS Score
8.2
EPSS Score
0.0%
EPSS Percentile
0th

Plate is a rich-text editor with AI and shadcn/ui. Prior to 53.3.2, @platejs/docx-io fetches remote image URLs while converting attacker-controlled HTML through htmlToDocxBlob in a server-side or privileged environment. The converter can make requests to internal network resources and include the fetched image bytes in the generated DOCX, allowing server-side request forgery with response disclosure. Applications can also incur resource consumption from attacker-selected remote responses. This issue is fixed in version 53.3.2.

CWE CWE-918
Vendor udecode
Product plate
Published Aug 20, 2026
Stay Ahead of the Next One

Get instant alerts for udecode plate

Be the first to know when new high vulnerabilities affecting udecode plate are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
Low

Affected Versions

udecode / plate
< 53.3.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/udecode/plate/security/advisories/GHSA-4q39-2jhr-7qx8 github.com: https://github.com/udecode/plate/pull/5053 github.com: https://github.com/udecode/plate/commit/21aa59926f4bbd421027354823cca09c6700ed73 github.com: https://github.com/udecode/plate/releases/tag/v53.3.2