THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-qj6x-xx2h-8hvv (high) — Plate: Media embed provider metadata can bypass URL sanitization and execute iframe JavaScript

[GHSA] GHSA-qj6x-xx2h-8hvv (high) — Plate: Media embed provider metadata can bypass URL sanitization and execute iframe JavaScript

highgithub_advisoriesPublished 2026-08-25

GHSA-qj6x-xx2h-8hvv Severity: high CVE: CVE-2026-55596

Plate: Media embed provider metadata can bypass URL sanitization and execute iframe JavaScript

## Summary

The media embed renderer trusts serialized `provider` or `sourceUrl` metadata and skips the URL protocol validation that normally blocks unsafe media embed URLs. A crafted Plate document can set a known video provider while keeping `url

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-qj6x-xx2h-8hvv