GHSA-qj6x-xx2h-8hvv
HIGHCVE-2026-55596The media embed renderer trusts serialized provider or sourceUrl metadata and skips the URL protocol validation that normally blocks unsafe media embed URLs. A crafted Plate document can set a known video provider while keeping url as a javascript: iframe source. When a victim opens that document in an app using the registry media embed component, the component renders the attacker URL directly as
- Affected
- >= 53.0.0, < 53.1.4
- Fixed in
- 53.1.4
- Weakness
- CWE-79
- Published
- 2026-08-25
- Source
- github