Impact
Plate versions 53.0.0 through 53.1.3 contain a media‑embed rendering flaw that trusts provider or sourceUrl metadata and skips protocol validation, allowing a crafted document to set a known video provider while keeping a javascript: iframe source, which the registry’s MediaEmbedElement renders directly and executes the script when the victim opens the document, thereby enabling arbitrary client‑side code to run and potentially exfiltrate data; this is a classic CWE‑79 vulnerability fixed in release 53.1.4.
Affected Systems
The udecode:plate rich‑text editor from version 53.0.0 through 53.1.3 is affected; installing any of these releases and rendering media embeds from untrusted content can expose the system to the flaw, while the first patched release is 53.1.4 which restores proper protocol validation for media URLs.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, and the EPSS score of less than 1% suggests a very low but non‑zero likelihood of exploitation; the vulnerability is not listed in the CISA KEV catalogue, indicating no publicly known mass exploitation, and the most likely attack vector is a malicious Plate document that a user opens—either from a shared file or via a collaboration link—causing the embedded iframe to source an attacker‑controlled javascript: URL that triggers code execution within the victim’s browser context.
OpenCVE Enrichment