VYPR

npm package

@udecode/plate-link

pkg:npm/%40udecode/plate-link

Vulnerabilities (1)

  • CVE-2023-34245Jun 9, 2023
    affected < 20.0.0fixed 20.0.0

    @udecode/plate-link is the link handler for the udecode/plate rich-text editor plugin system for Slate & React. Affected versions of the link plugin and link UI component do not sanitize URLs to prevent use of the `javascript:` scheme. As a result, links with JavaScript URLs can