{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-55596/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.7,"id":"CVE-2026-55596"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["@platejs/media"],"_cs_severities":["high"],"_cs_tags":["xss","injection","web-application","cve-2026-55596"],"_cs_type":"advisory","_cs_vendors":["Plate"],"content_html":"\u003cp\u003eThe Plate media embed component, specifically the \u003ccode\u003e@platejs/media\u003c/code\u003e package (versions 53.0.0 through 53.1.3), contains a critical flaw that allows for Stored Cross-Site Scripting (XSS). The vulnerability exists because the library's \u003ccode\u003euseMediaState\u003c/code\u003e hook contains a fast-path optimization that incorrectly trusts serialized document metadata (\u003ccode\u003eprovider\u003c/code\u003e, \u003ccode\u003esourceUrl\u003c/code\u003e, and \u003ccode\u003eid\u003c/code\u003e) without re-validating the \u003ccode\u003eurl\u003c/code\u003e parameter.\u003c/p\u003e\n\u003cp\u003eBy crafting a Plate document that specifies a legitimate video provider (e.g., \u003ccode\u003evimeo\u003c/code\u003e) but provides an arbitrary \u003ccode\u003eurl\u003c/code\u003e field containing \u003ccode\u003ejavascript:\u003c/code\u003e URIs, an attacker can bypass the intended \u003ccode\u003eparseMediaUrl\u003c/code\u003e sanitization logic. When a victim opens a document containing this malicious node, the registry \u003ccode\u003eMediaEmbedElement\u003c/code\u003e trusts the attacker-supplied \u003ccode\u003eprovider\u003c/code\u003e metadata and proceeds to render the malicious \u003ccode\u003eurl\u003c/code\u003e directly into an \u003ccode\u003e\u0026lt;iframe\u0026gt;\u003c/code\u003e src attribute. This results in the execution of JavaScript within the context of the host application, potentially leading to session hijacking or sensitive data exfiltration.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for arbitrary JavaScript execution in the victim's browser context. The impact is dependent on the host application's session model and document access permissions. In collaborative environments, this could lead to widespread XSS against users who view maliciously crafted documents. The vulnerability is addressed in \u003ccode\u003e@platejs/media\u003c/code\u003e version 53.1.4.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade the \u003ccode\u003e@platejs/media\u003c/code\u003e package to version 53.1.4 or later immediately.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation on the client side to ensure the \u003ccode\u003eurl\u003c/code\u003e field in media embeds uses only \u003ccode\u003ehttp:\u003c/code\u003e or \u003ccode\u003ehttps:\u003c/code\u003e protocols.\u003c/li\u003e\n\u003cli\u003eTreat all serialized metadata, including \u003ccode\u003eprovider\u003c/code\u003e, \u003ccode\u003esourceUrl\u003c/code\u003e, and \u003ccode\u003eid\u003c/code\u003e, as untrusted; always recompute these values from the \u003ccode\u003eurl\u003c/code\u003e field using \u003ccode\u003eparseMediaUrl\u003c/code\u003e rather than relying on cached serialized data.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-25T18:50:10Z","date_published":"2026-08-25T18:50:10Z","id":"https://feed.craftedsignal.io/briefs/2026-08-plate-media-xss/","summary":"A vulnerability in the Plate @platejs/media package allows attackers to bypass URL sanitization and achieve Cross-Site Scripting (XSS) by embedding malicious JavaScript URIs in media documents (CVE-2026-55596).","title":"Cross-Site Scripting Vulnerability in Plate Media Embed Renderer","url":"https://feed.craftedsignal.io/briefs/2026-08-plate-media-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-55596","version":"https://jsonfeed.org/version/1.1"}