{"id":"CVE-2026-55596","summary":"Plate: Media embed provider metadata can bypass URL sanitization and execute iframe JavaScript","details":"Plate is a rich-text editor with AI and shadcn/ui. From 53.0.0 until 53.1.4, the media embed renderer trusts serialized provider or sourceUrl metadata in useMediaState and skips parseMediaUrl protocol validation, allowing a crafted Plate document to set a known video provider while keeping url as a javascript: iframe source that the registry MediaEmbedElement renders directly as an iframe src when a victim opens the document. This issue is fixed in version 53.1.4.","aliases":["GHSA-qj6x-xx2h-8hvv"],"modified":"2026-08-12T03:51:37.794647281Z","published":"2026-07-08T20:27:58.987Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55596.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-79"]},"references":[{"type":"WEB","url":"https://github.com/udecode/plate/releases/tag/v53.1.4"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55596.json"},{"type":"ADVISORY","url":"https://github.com/udecode/plate/security/advisories/GHSA-qj6x-xx2h-8hvv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55596"},{"type":"FIX","url":"https://github.com/udecode/plate/commit/6214914ca811adf22d0ad503154494216eed68ba"},{"type":"FIX","url":"https://github.com/udecode/plate/pull/5014"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/udecode/plate","events":[{"introduced":"7b9b204e1e38a20b1f8bec5a900d67c64afbc525"},{"fixed":"6214914ca811adf22d0ad503154494216eed68ba"},{"fixed":"c5b8e60148c5fbe4c8047cd5cf049127c6091314"}],"database_specific":{"extracted_events":[{"introduced":"53.0.0"},{"fixed":"53.1.4"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v53.1.3","@platejs/list@53.1.3","v53.1.2","platejs@53.1.2","@platejs/utils@53.1.2","@platejs/core@53.1.2","v53.1.1","@platejs/markdown@53.1.1","@platejs/ai@53.1.1","v53.1.0","@platejs/docx-io@53.1.0","@platejs/dnd@53.1.0","v53.0.9","@platejs/table@53.0.9","@platejs/csv@53.0.9","@platejs/ai@53.0.9","v53.0.8","@platejs/docx-io@53.0.8","v53.0.7","platejs@53.0.7","@platejs/utils@53.0.7","@platejs/test-utils@53.0.7","@platejs/table@53.0.7","@platejs/slate@53.0.7","@platejs/csv@53.0.7","@platejs/core@53.0.7","@platejs/ai@53.0.7","v53.0.6","platejs@53.0.6","@platejs/utils@53.0.6","@platejs/core@53.0.6","v53.0.5","platejs@53.0.5","@platejs/utils@53.0.5","@platejs/test-utils@53.0.5","@platejs/slate@53.0.5","@platejs/core@53.0.5","@platejs/markdown@53.0.4","@platejs/ai@53.0.4","platejs@53.0.3","@platejs/utils@53.0.3","@platejs/suggestion@53.0.3","@platejs/link@53.0.3","@platejs/ai@53.0.3","@platejs/list@53.0.2","@platejs/media@53.0.1","platejs@53.0.0","@platejs/yjs@53.0.0","@platejs/utils@53.0.0","@platejs/toggle@53.0.0","@platejs/toc@53.0.0","@platejs/test-utils@53.0.0","@platejs/tag@53.0.0","@platejs/table@53.0.0","@platejs/tabbable@53.0.0","@platejs/suggestion@53.0.0","@platejs/slate@53.0.0","@platejs/slash-command@53.0.0","@platejs/selection@53.0.0","@platejs/resizable@53.0.0","@platejs/playwright@53.0.0","@platejs/mention@53.0.0","@platejs/media@53.0.0","@platejs/math@53.0.0","@platejs/markdown@53.0.0","@platejs/list@53.0.0","@platejs/list-classic@53.0.0","@platejs/link@53.0.0","@platejs/layout@53.0.0","@platejs/juice@53.0.0","@platejs/indent@53.0.0","@platejs/footnote@53.0.0","@platejs/floating@53.0.0","@platejs/find-replace@53.0.0","@platejs/excalidraw@53.0.0","@platejs/emoji@53.0.0","@platejs/docx@53.0.0","@platejs/docx-io@53.0.0","@platejs/dnd@53.0.0","@platejs/diff@53.0.0","@platejs/date@53.0.0","@platejs/cursor@53.0.0","@platejs/csv@53.0.0","@platejs/core@53.0.0","@platejs/comment@53.0.0","@platejs/combobox@53.0.0","@platejs/code-drawing@53.0.0","@platejs/code-block@53.0.0","@platejs/caption@53.0.0","@platejs/callout@53.0.0","@platejs/basic-styles@53.0.0","@platejs/basic-nodes@53.0.0","@platejs/autoformat@53.0.0","@platejs/ai@53.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-55596.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"}]}