Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-88976— @platejs/core HTML deserialization can trigger browser behavior during parsing

Quick assessment

Affected
udecode plate
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Plate 是一款集成了 AI 功能和 shadcn/ui 的富文本编辑器。在 53.3.11 之前,以及在已停止维护的 54.0.0-beta.0 至 54.0.0-beta.1 版本中,Plate 核心的 HTML 反序列化 API 会解析传入当前文档的 HTML 字符串。当应用向这些 API 传递来自不可信来源或跨用户的 HTML 时,某些 HTML 属性可能在 HTML 被转换为编辑器节点之前,先触发浏览器的特定行为。这可能导致在用户加载反序列化内容时,攻击者控制的脚本在宿主应用的源(origin)中执行。

CVSS 6.1 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-88976

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
@platejs/core HTML deserialization can trigger browser behavior during parsing
Source: CVE Program / CVE List V5
Vulnerability Description
Plate is a rich-text editor with AI and shadcn/ui. Prior to 53.3.11, and in the discontinued 54.0.0-beta.0 through 54.0.0-beta.1 builds, Plate core HTML deserialization APIs parse supplied HTML strings in the active document. When an application passes untrusted or cross-user HTML to these APIs, certain HTML attributes can trigger browser behavior before the HTML is converted into editor nodes. This can allow attacker-controlled script to execute in the consuming application's origin when another user loads the deserialized content. This issue is fixed in version 53.3.11.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
udecode plate < 53.3.11 -

II. Public POCs for CVE-2026-88976

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-88976

登录查看更多情报信息。

Patches & Fixes for CVE-2026-88976 (2)

Vendor Advisories for CVE-2026-88976 (1)

Vendor Pages for CVE-2026-88976 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-88976

No comments yet


Leave a comment