VYPR

@platejs/docx-io

by Udecode

CVEs (1)

  • CVE-2026-65842HigAug 20, 2026
    risk 0.46cvss 8.2epss

    Plate is a rich-text editor with AI and shadcn/ui. Prior to 53.3.2, @platejs/docx-io fetches remote image URLs while converting attacker-controlled HTML through htmlToDocxBlob in a server-side or privileged environment. The converter can make requests to internal network…