mediumCVSS 6.1Vulnerability

CVE-2026-88976

### Summary HTML strings passed to Plate's core deserialization APIs were parsed in the active document. Certain HTML attributes could therefore trigger browser behavior during parsing, before the content was converted into editor nodes. Applications that deserialize HTML from untrusted or cross-user sources may be affected. ### Impact An attacker who can control HTML later deserialized in another user's browser may be able to execute script in that application's origin. ### Remediation Upgrade to `@platejs/core` 53.3.11 or later. Users of the discontinued 54.0.0 beta builds should install the fixed stable line. Applications should also sanitize untrusted HTML before rendering it; inert parsing is not a substitute for sanitization.

Properties

ghsa_id
GHSA-qrfj-mgw8-j9c6
severity
medium
summary
@platejs/core HTML deserialization can trigger browser behavior during parsing
cvss_score
6.1
cve_id
CVE-2026-88976
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
signal_observed_at
2026-09-17T21:32:39+00:00
is_ghsa_only
false
ghsa_published
2026-09-17T20:32:47Z
source_url
https://github.com/advisories/GHSA-qrfj-mgw8-j9c6
ghsa_updated
2026-09-17T20:32:51Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]npm/@platejs/core

AFFECTS (1)

[Software]npm/@platejs/core

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-88976 (CVSS 6.1) — Ninja Signal Threat Intelligence | Ninja Signal