THREAT OPS › Threat News › [GHSA] GHSA-qj6x-xx2h-8hvv (high) — Plate: Media embed provider metadata can bypass URL sanitization and execute iframe JavaScript
[GHSA] GHSA-qj6x-xx2h-8hvv (high) — Plate: Media embed provider metadata can bypass URL sanitization and execute iframe JavaScript
GHSA-qj6x-xx2h-8hvv Severity: high CVE: CVE-2026-55596
Plate: Media embed provider metadata can bypass URL sanitization and execute iframe JavaScript
## Summary
The media embed renderer trusts serialized `provider` or `sourceUrl` metadata and skips the URL protocol validation that normally blocks unsafe media embed URLs. A crafted Plate document can set a known video provider while keeping `url
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- CVE-2026-55596cve
- https://vimeo.com/1url
Original source: https://github.com/advisories/GHSA-qj6x-xx2h-8hvv