Junglewise Threat Intelligence

CVE-2026-55596: udecode Plate XSS in media embed renderer

CVE-2026-55596 · Severity: high · CVSS 8.7 · Published 2026-07-08

Vendors: npm.

Executive brief

Plate is a rich-text editor library used in web applications to render documents with embedded media content such as videos. A vulnerability in the media embed component allows an attacker to bypass URL validation by crafting a malicious document that specifies a legitimate video provider (like Vimeo) while injecting a malicious JavaScript URL. When a victim opens this document, the JavaScript executes in the victim's browser, potentially exposing sensitive data or performing unauthorized actions on their behalf.

Technical details

The vulnerability is a stored cross-site scripting (XSS) flaw in the `useMediaState` hook within `@platejs/media`. The intended security hardening point, `parseMediaUrl`, validates that embed URLs use only `http:` or `https:` protocols and rejects unsafe schemes. However, `useMediaState` includes a fast path for serialized Plate documents that already contain `provider` or `sourceUrl` metadata. This fast path bypasses `parseMediaUrl` and directly returns the untrusted `url` field without validation. The registry `MediaEmbedElement` then renders non-YouTube providers with `<iframe src={embed.url}>`, allowing an attacker to set `provider` to a legitimate value (e.g., "vimeo") while setting `url` to a `javascript:` URI. The fix, released in `@platejs/media` 53.1.4, recomputes embed metadata from the render URL instead of trusting serialized metadata fields.

Affected products

  • udecode @platejs/media >=53.0.0, <53.1.4

Timeline

  • 2026-06-14: disclosed
  • 2026-06-14: patched: @platejs/media 53.1.4 released
  • 2026-08-25: advisory: GHSA-qj6x-xx2h-8hvv published to GitHub Advisory Database

References

Related threats