Executive brief
Plate, a rich text editor framework, allows arbitrary DOM attributes to be injected into rendered HTML elements through the element.attributes and leaf.attributes properties. This can enable cross-site scripting attacks and information exposure attacks (IP address leakage) when malicious documents are opened or pasted. Applications that restrict external resource loading are at particular risk of IP address disclosure through crafted style or other request-triggering attributes.
Technical details
The vulnerability is a DOM injection flaw in Plate's attribute handling mechanism. The getRenderNodeProps function passes arbitrary user-controlled attributes from element.attributes and leaf.attributes directly into the nodeProps object, which is then spread onto DOM elements (e.g., {...attributes} {...nodeProps}). Attackers can deliver malicious content via malicious documents stored on the server, pasted fragments, or collaborative operations. Depending on component implementation, this can lead to XSS via href/src attributes on links and iframes, or information exposure via style and other attributes that trigger web requests. The patched versions (38.0.6, 36.5.9, 21.5.1 and later) disable arbitrary attributes by default and require explicit opt-in via the dangerouslyAllowAttributes configuration option.
Affected products
- Udecode plate-core >=37.0.0, <38.0.6; >=22.0.0, <36.5.9; <21.5.1
Timeline
- 2024-09-20: disclosed