VYPR

npm package

@platejs/docx-io

pkg:npm/%40platejs/docx-io

Vulnerabilities (1)

  • CVE-2026-65842HigAug 20, 2026
    affected < 53.3.2fixed 53.3.2

    Plate is a rich-text editor with AI and shadcn/ui. Prior to 53.3.2, @platejs/docx-io fetches remote image URLs while converting attacker-controlled HTML through htmlToDocxBlob in a server-side or privileged environment. The converter can make requests to internal network resource