Description
Plate is a rich-text editor with AI and shadcn/ui. Prior to 53.3.11, and in the discontinued 54.0.0-beta.0 through 54.0.0-beta.1 builds, Plate core HTML deserialization APIs parse supplied HTML strings in the active document. When an application passes untrusted or cross-user HTML to these APIs, certain HTML attributes can trigger browser behavior before the HTML is converted into editor nodes. This can allow attacker-controlled script to execute in the consuming application's origin when another user loads the deserialized content. This issue is fixed in version 53.3.11.
Published: 2026-09-16
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Script Execution via Cross‑Site Scripting
Action: Apply Patch
AI Analysis

Impact

The Plate rich‑text editor parses supplied HTML strings when deserializing content. Prior to version 53.3.11, any HTML – even from other users – is processed and certain attributes can trigger browser behavior before the content is converted into editor nodes. This allows an attacker to embed script‑containing attributes that execute code in the consuming application’s origin when a different user loads the deserialized content, resulting in script execution by the victim’s browser.

Affected Systems

The vulnerability affects the udecode:plate product. All releases before 53.3.11, including the discontinued 54.0.0‑beta.0 and 54.0.0‑beta.1 builds, are susceptible.

Risk and Exploitability

The CVSS score of 6.1 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation at the time of this analysis; the vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is likely via a web page that loads maliciously crafted HTML; the attacker only needs to provide the content and convince a victim to load it. Proper privilege checks are not applied during deserialization, enabling the embedded scripts to run in the victim’s context.

Generated by OpenCVE AI on September 18, 2026 at 02:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Plate to v53.3.11 or newer to remove the vulnerability.
  • Limit HTML deserialization to trusted content only; for user‑provided content, perform server‑side sanitization before passing the HTML to Plate APIs.
  • Enable a strict Content Security Policy that blocks inline scripts and restricts script execution to mitigate the impact of any remaining deserialization issues.

Generated by OpenCVE AI on September 18, 2026 at 02:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-qrfj-mgw8-j9c6 @platejs/core HTML deserialization can trigger browser behavior during parsing
History

Thu, 17 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Udecode
Udecode plate
Vendors & Products Udecode
Udecode plate

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description Plate is a rich-text editor with AI and shadcn/ui. Prior to 53.3.11, and in the discontinued 54.0.0-beta.0 through 54.0.0-beta.1 builds, Plate core HTML deserialization APIs parse supplied HTML strings in the active document. When an application passes untrusted or cross-user HTML to these APIs, certain HTML attributes can trigger browser behavior before the HTML is converted into editor nodes. This can allow attacker-controlled script to execute in the consuming application's origin when another user loads the deserialized content. This issue is fixed in version 53.3.11.
Title @platejs/core HTML deserialization can trigger browser behavior during parsing
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T15:25:38.481Z

Reserved: 2026-09-10T16:02:31.342Z

Link: CVE-2026-88976

cve-icon Vulnrichment

Updated: 2026-09-16T15:24:13.346Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T15:18:05.850

Modified: 2026-09-16T16:17:20.227

Link: CVE-2026-88976

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T03:00:09Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')