HIGH 8.7 GitHub
CVE-2026-55596
Plate: Media embed provider metadata can bypass URL sanitization and execute iframe JavaScript
## Summary
The media embed renderer trusts serialized `provider` or `sourceUrl` metadata and skips the URL protocol validation that normally blocks unsafe media embed URLs. A crafted Plate document can set a known video provider while keeping `url` as a `javascript:` iframe source. When a victim opens that document in an app using the registry media embed component, the component renders the attacker URL directly as an iframe `src`.
## Impact
An attacker who can create or share Plate document
Affected Products
- npm/@platejs/media >= 53.0.0, < 53.1.4
References
- https://github.com/advisories/GHSA-qj6x-xx2h-8hvv
- https://github.com/udecode/plate/security/advisories/GHSA-qj6x-xx2h-8hvv
- https://nvd.nist.gov/vuln/detail/CVE-2026-55596
- https://github.com/udecode/plate/pull/5014
This high severity vulnerability with a CVSS score of 8.7 was published on 2026-08-25 via GitHub. Affected: npm/@platejs/media >= 53.0.0, < 53.1.4.
vulnfeed aggregates 11954 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.