Vulnerabilities/

Plate media plugins has a XSS in media embed element when using custom URL parsers

Severity:
High

Description

Editors that use MediaEmbedElement and pass custom urlParsers to the useMediaState hook may be vulnerable to XSS if a custom parser allows javascript:, data: or vbscript: URLs to be embedded. Editors that do not use urlParsers and instead consume the url property directly may also be vulnerable if the URL is not sanitised.

Recommendation

Update the @udecode/plate-media package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@udecode/plate-media
Anything's wrong? Let us know Last updated on August 04, 2024