Impact
The Plate rich‑text editor parses supplied HTML strings when deserializing content. Prior to version 53.3.11, any HTML – even from other users – is processed and certain attributes can trigger browser behavior before the content is converted into editor nodes. This allows an attacker to embed script‑containing attributes that execute code in the consuming application’s origin when a different user loads the deserialized content, resulting in script execution by the victim’s browser.
Affected Systems
The vulnerability affects the udecode:plate product. All releases before 53.3.11, including the discontinued 54.0.0‑beta.0 and 54.0.0‑beta.1 builds, are susceptible.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation at the time of this analysis; the vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is likely via a web page that loads maliciously crafted HTML; the attacker only needs to provide the content and convince a victim to load it. Proper privilege checks are not applied during deserialization, enabling the embedded scripts to run in the victim’s context.
OpenCVE Enrichment
Github GHSA