HIGH 8.7 GitHub

CVE-2026-55596

Plate: Media embed provider metadata can bypass URL sanitization and execute iframe JavaScript

## Summary The media embed renderer trusts serialized `provider` or `sourceUrl` metadata and skips the URL protocol validation that normally blocks unsafe media embed URLs. A crafted Plate document can set a known video provider while keeping `url` as a `javascript:` iframe source. When a victim opens that document in an app using the registry media embed component, the component renders the attacker URL directly as an iframe `src`. ## Impact An attacker who can create or share Plate document

Affected Products

References

Published: 2026-08-25 · Source: GitHub · Feed updated: 2026-08-25
This high severity vulnerability with a CVSS score of 8.7 was published on 2026-08-25 via GitHub. Affected: npm/@platejs/media >= 53.0.0, < 53.1.4.
vulnfeed aggregates 11954 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.