Security: udecode/plate
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
Unsafe image-preview download destinations in Plate UIGHSA-r3c4-jjfg-3vvx published
Sep 7, 2026 by zbeyensModerate -
Document-view denial of service from incomplete equation contentGHSA-p8g2-cf33-p28j published
Sep 7, 2026 by zbeyensModerate -
Unauthorized AI service usage in copied Plate route examplesGHSA-2q2r-jqh4-grp3 published
Sep 7, 2026 by zbeyensModerate -
Missing upload authorization in copied Plate service examplesGHSA-6gwv-m56p-wc8m published
Sep 7, 2026 by zbeyensModerate -
Improper validation of equation metadata in @platejs/docx-io DOCX exportsGHSA-5pmq-h882-6g62 published
Sep 4, 2026 by zbeyensModerate -
Improper HTML escaping in @platejs/core serialization can enable stored XSSGHSA-fm23-57g4-6m2p published
Sep 4, 2026 by zbeyensModerate -
@platejs/core HTML deserialization can trigger browser behavior during parsingGHSA-qrfj-mgw8-j9c6 published
Sep 4, 2026 by zbeyensModerate -
Cross-site scripting through serialized Markdown link contentGHSA-vjm2-6pxg-8vm8 published
Sep 7, 2026 by zbeyensModerate -
Command injection through untrusted dependency metadata in depsetGHSA-q8r4-6wh4-76hm published
Sep 7, 2026 by zbeyensHigh -
SSRF with response disclosure in DOCX image embeddingGHSA-4q39-2jhr-7qx8 published
Jul 3, 2026 by zbeyensHigh
Learn more about advisories related to udecode/plate in the GitHub Advisory Database