Vulnerabilities/

@udecode/plate-link does not sanitize URLs to prevent use of the `javascript:` scheme

Severity:
High

Description

Affected versions of the link plugin and link UI component do not sanitize URLs to prevent use of the javascript: scheme. As a result, links with JavaScript URLs can be inserted into the Plate editor through various means, including opening or pasting malicious content.

Recommendation

Update the @udecode/plate-link package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@udecode/plate-link
Anything's wrong? Let us know Last updated on November 10, 2023