GHSA-qrfj-mgw8-j9c6: XSS

Published Sep 17, 2026
·
Updated

Summary

HTML strings passed to Plate's core deserialization APIs were parsed in the active document. Certain HTML attributes could therefore trigger browser behavior during parsing, before the content was converted into editor nodes.

Applications that deserialize HTML from untrusted or cross-user sources may be affected.

Impact

An attacker who can control HTML later deserialized in another user's browser may be able to execute script in that application's origin.

Remediation

Upgrade to @platejs/core 53.3.11 or later. Users of the discontinued 54.0.0 beta builds should install the fixed stable line. Applications should also sanitize untrusted HTML before rendering it; inert parsing is not a substitute for sanitization.

Affected Software

2 affected componentsFixes available
npm/@platejs/core>=54.0.0-beta.0<=54.0.0-beta.1
npm/@platejs/core<53.3.11
53.3.11

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/@platejs/core to a version that resolves this vulnerability.

    Fixed in 53.3.11
  2. Upgrade

    Upgrade @platejs/core to a version that resolves this vulnerability.

    Fixed in 53.3.11

Event History

Sep 17, 2026
Advisory Published
via GitHub·08:32 PM
Data Sourced
via GitHub·08:32 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which applications are exposed?

Applications using @platejs/core that deserialize HTML from untrusted or cross-user sources in another user's browser may be affected. The attacker must be able to control HTML that is later deserialized by a victim.

2

What attacker interaction is required?

The attacker does not need privileges, but a user must cause the attacker-controlled HTML to be deserialized in their browser. Malicious HTML attributes can trigger browser behavior during parsing, before conversion into editor nodes.

3

What should be done if upgrading is not immediately possible?

Sanitize all untrusted HTML before it is rendered or deserialized. Inert parsing alone is not considered a replacement for sanitization.

4

Which versions should be used for remediation?

Upgrade @platejs/core to version 53.3.11 or later. Users on the discontinued 54.0.0 beta builds should move to the fixed stable line.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203