Executive brief
Plate is a rich-text editor library used in web applications to render documents with embedded media content such as videos. A vulnerability in the media embed component allows an attacker to bypass URL validation by crafting a malicious document that specifies a legitimate video provider (like Vimeo) while injecting a malicious JavaScript URL. When a victim opens this document, the JavaScript executes in the victim's browser, potentially exposing sensitive data or performing unauthorized actions on their behalf.
Technical details
The vulnerability is a stored cross-site scripting (XSS) flaw in the `useMediaState` hook within `@platejs/media`. The intended security hardening point, `parseMediaUrl`, validates that embed URLs use only `http:` or `https:` protocols and rejects unsafe schemes. However, `useMediaState` includes a fast path for serialized Plate documents that already contain `provider` or `sourceUrl` metadata. This fast path bypasses `parseMediaUrl` and directly returns the untrusted `url` field without validation. The registry `MediaEmbedElement` then renders non-YouTube providers with `<iframe src={embed.url}>`, allowing an attacker to set `provider` to a legitimate value (e.g., "vimeo") while setting `url` to a `javascript:` URI. The fix, released in `@platejs/media` 53.1.4, recomputes embed metadata from the render URL instead of trusting serialized metadata fields.
Affected products
- udecode @platejs/media >=53.0.0, <53.1.4
Timeline
- 2026-06-14: disclosed
- 2026-06-14: patched: @platejs/media 53.1.4 released
- 2026-08-25: advisory: GHSA-qj6x-xx2h-8hvv published to GitHub Advisory Database