A high-severity cross-site scripting flaw, tracked as CVE-2026-55596, was disclosed in the udecode Plate rich-text editor after researchers found that the @platejs/media component trusted serialized provider and sourceUrl metadata when rendering embedded media. In affected versions 53.0.0 through before 53.1.4, an attacker with the ability to craft a Plate document could mark content as a known video provider while supplying a javascript: iframe source, causing unsafe content to be rendered when a victim opened the document. The issue is classified as CWE-79 and carries a CVSS 3.1 vector of AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N.
Plate maintainers fixed the bug in version 53.1.4 by removing the code path that trusted serialized media metadata and instead deriving embed state from the parsed render URL. The patch was merged through pull request #5014 and corresponding commit 6214914ca811adf22d0ad503154494216eed68ba, with regression tests added to ensure unsafe serialized metadata no longer produces embeds and that provider information is recalculated from the actual URL. Organizations using Plate media embeds should upgrade to 53.1.4 or later to prevent malicious documents from triggering iframe-based script execution.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
NVD metadata for CVE-2026-55596 was updated and the vulnerability analysis was finalized. This followed the public disclosure and advisory publication for the Plate media embed XSS flaw.
A public advisory described CVE-2026-55596, a cross-site scripting vulnerability in Plate versions 53.0.0 through before 53.1.4 that let crafted documents bypass URL sanitization and execute javascript: iframe sources. The advisory also referenced the fix, pull request, commit, and release materials.
Plate released version 53.1.4 to address the media embed rendering issue, rejecting unsafe serialized iframe URLs. The release notes tied the fix to pull request #5014 and identified it as a security-related update for @platejs/media.
The Plate project merged pull request #5014, a security bugfix for the media plugin that derives embed metadata from the render URL instead of trusting serialized provider metadata. The PR explicitly addressed unsafe handling of javascript: URLs in media embed flows.
A security bug fix was committed to the udecode Plate project to stop serialized media metadata from bypassing URL parsing and allowing unsafe iframe render URLs. The change removed trust in serialized provider/sourceUrl metadata and added regression tests for the advisory proof of concept.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
cvereports.com
Open sourcecvefeed.io
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.