HTML Deserialization Vulnerability in Plate Rich-Text Editor by udecode
CVE-2026-88976

6.1MEDIUM

Key Information:

Vendor

Udecode

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-88976?

The Plate rich-text editor, prior to version 53.3.11 and in certain beta builds, contains a vulnerability in its core HTML deserialization APIs. This flaw arises when the application processes untrusted or cross-user HTML input. Specific HTML attributes can manipulate browser behavior, potentially leading to the execution of attacker-controlled scripts within the application's origin when another user accesses the deserialized content. This issue has been addressed in the release of version 53.3.11.

Affected Version(s)

plate < 53.3.11 < 53.3.11

plate >= 54.0.0-beta.0, <= 54.0.0-beta.1 <= 54.0.0-beta.0, 54.0.0-beta.1

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.