VYPR

npm package

@udecode/plate-media

pkg:npm/%40udecode/plate-media

Vulnerabilities (1)

  • CVE-2024-40631HigJul 15, 2024
    affected < 36.0.10fixed 36.0.10

    Plate media is an open source, rich-text editor for React. Editors that use `MediaEmbedElement` and pass custom `urlParsers` to the `useMediaState` hook may be vulnerable to XSS if a custom parser allows `javascript:`, `data:` or `vbscript:` URLs to be embedded. Editors that do n