๐Ÿ” CVE Alert

CVE-2026-88976

MEDIUM 6.1

@platejs/core HTML deserialization can trigger browser behavior during parsing

CVSS Score
6.1
EPSS Score
0.0%
EPSS Percentile
0th

Plate is a rich-text editor with AI and shadcn/ui. Prior to 53.3.11, and in the discontinued 54.0.0-beta.0 through 54.0.0-beta.1 builds, Plate core HTML deserialization APIs parse supplied HTML strings in the active document. When an application passes untrusted or cross-user HTML to these APIs, certain HTML attributes can trigger browser behavior before the HTML is converted into editor nodes. This can allow attacker-controlled script to execute in the consuming application's origin when another user loads the deserialized content. This issue is fixed in version 53.3.11.

CWE CWE-79
Vendor udecode
Product plate
Published Sep 16, 2026
Last Updated Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for udecode plate

Be the first to know when new medium vulnerabilities affecting udecode plate are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

udecode / plate
< 53.3.11 >= 54.0.0-beta.0, <= 54.0.0-beta.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/udecode/plate/security/advisories/GHSA-qrfj-mgw8-j9c6 github.com: https://github.com/udecode/plate/pull/5117 github.com: https://github.com/udecode/plate/commit/d02afe45d5ec3a9fb95e0745bc5820ff18a3c12b github.com: https://github.com/udecode/plate/releases/tag/v53.3.11