HTML Deserialization Vulnerability in Plate Rich-Text Editor by udecode
CVE-2026-88976
6.1MEDIUM
What is CVE-2026-88976?
The Plate rich-text editor, prior to version 53.3.11 and in certain beta builds, contains a vulnerability in its core HTML deserialization APIs. This flaw arises when the application processes untrusted or cross-user HTML input. Specific HTML attributes can manipulate browser behavior, potentially leading to the execution of attacker-controlled scripts within the application's origin when another user accesses the deserialized content. This issue has been addressed in the release of version 53.3.11.
Affected Version(s)
plate < 53.3.11 < 53.3.11
plate >= 54.0.0-beta.0, <= 54.0.0-beta.1 <= 54.0.0-beta.0, 54.0.0-beta.1
