{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aplatedocx-io/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:plate:docx-io:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.2,"id":"CVE-2026-65842"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["@platejs/docx-io (\u003c 53.3.2)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","ssrf","data-exfiltration"],"_cs_type":"advisory","_cs_vendors":["Plate"],"content_html":"\u003cp\u003eThe \u003ccode\u003e@platejs/docx-io\u003c/code\u003e library, versions prior to 53.3.2, contains a vulnerability where the HTML-to-DOCX conversion process insecurely fetches remote image URLs provided in the input HTML. When an application processes untrusted, attacker-controlled HTML in a server-side context, it triggers an outbound HTTP request from the host environment to the URL specified in the HTML.\u003c/p\u003e\n\u003cp\u003eThis vulnerability (CVE-2026-65842) poses a significant risk for environments where internal network resources are accessible to the server running the conversion. Because the library embeds the fetched image data into the generated DOCX file, an attacker can leverage this mechanism to exfiltrate data from otherwise unreachable internal services or probe for open ports and services, resulting in a server-side response disclosure. Defenders should ensure all input is sanitized or processed in a network-isolated environment.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability affects applications that utilize \u003ccode\u003e@platejs/docx-io\u003c/code\u003e to convert untrusted HTML into DOCX files, particularly in server-side workflows. Successful exploitation enables unauthorized internal network probing and potential leakage of sensitive internal data into the exported document. All users are urged to upgrade to version 53.3.2 or later to mitigate the risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the \u003ccode\u003e@platejs/docx-io\u003c/code\u003e package to version 53.3.2 or later immediately to patch CVE-2026-65842.\u003c/li\u003e\n\u003cli\u003eImplement strict input sanitization on all user-supplied HTML before it reaches the conversion engine to strip remote image source references.\u003c/li\u003e\n\u003cli\u003eConvert any necessary remote images into Base64-encoded Data URIs within the application layer prior to calling the library for DOCX conversion.\u003c/li\u003e\n\u003cli\u003eIsolate the conversion process within a sandboxed environment or a container with egress-restricted network access to prevent unauthorized outbound requests.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-03T00:03:43Z","date_published":"2026-09-03T00:03:43Z","id":"https://feed.craftedsignal.io/briefs/2026-09-plate-ssrf/","summary":"The @platejs/docx-io library is vulnerable to Server-Side Request Forgery (SSRF) and response disclosure, allowing attackers to probe internal networks via malicious HTML image embeddings.","title":"SSRF and Response Disclosure in @platejs/docx-io","url":"https://feed.craftedsignal.io/briefs/2026-09-plate-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:plate:docx-Io:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}