{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-88976","assignerOrgId":"a0819718-46f1-4df5-94e2-005712e83aaa","state":"PUBLISHED","assignerShortName":"GitHub_M","dateReserved":"2026-09-10T16:02:31.342Z","datePublished":"2026-09-16T14:11:39.881Z","dateUpdated":"2026-09-16T15:25:38.481Z"},"containers":{"cna":{"title":"@platejs/core HTML deserialization can trigger browser behavior during parsing","problemTypes":[{"descriptions":[{"cweId":"CWE-79","lang":"en","description":"CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","type":"CWE"}]}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","version":"3.1"}}],"references":[{"name":"https://github.com/udecode/plate/security/advisories/GHSA-qrfj-mgw8-j9c6","tags":["x_refsource_CONFIRM"],"url":"https://github.com/udecode/plate/security/advisories/GHSA-qrfj-mgw8-j9c6"},{"name":"https://github.com/udecode/plate/pull/5117","tags":["x_refsource_MISC"],"url":"https://github.com/udecode/plate/pull/5117"},{"name":"https://github.com/udecode/plate/commit/d02afe45d5ec3a9fb95e0745bc5820ff18a3c12b","tags":["x_refsource_MISC"],"url":"https://github.com/udecode/plate/commit/d02afe45d5ec3a9fb95e0745bc5820ff18a3c12b"},{"name":"https://github.com/udecode/plate/releases/tag/v53.3.11","tags":["x_refsource_MISC"],"url":"https://github.com/udecode/plate/releases/tag/v53.3.11"}],"affected":[{"vendor":"udecode","product":"plate","versions":[{"version":"< 53.3.11","status":"affected"},{"version":">= 54.0.0-beta.0, <= 54.0.0-beta.1","status":"affected"}]}],"providerMetadata":{"orgId":"a0819718-46f1-4df5-94e2-005712e83aaa","shortName":"GitHub_M","dateUpdated":"2026-09-16T14:11:39.881Z"},"descriptions":[{"lang":"en","value":"Plate is a rich-text editor with AI and shadcn/ui. Prior to 53.3.11, and in the discontinued 54.0.0-beta.0 through 54.0.0-beta.1 builds, Plate core HTML deserialization APIs parse supplied HTML strings in the active document. When an application passes untrusted or cross-user HTML to these APIs, certain HTML attributes can trigger browser behavior before the HTML is converted into editor nodes. This can allow attacker-controlled script to execute in the consuming application's origin when another user loads the deserialized content. This issue is fixed in version 53.3.11."}],"source":{"advisory":"GHSA-qrfj-mgw8-j9c6","discovery":"UNKNOWN"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-09-16T15:24:04.653416Z","id":"CVE-2026-88976","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-16T15:25:38.481Z"}}]}}