THREAT OPS › Threat News › [GHSA] GHSA-4q39-2jhr-7qx8 (high) — Plate: SSRF with response disclosure in DOCX image embedding
[GHSA] GHSA-4q39-2jhr-7qx8 (high) — Plate: SSRF with response disclosure in DOCX image embedding
GHSA-4q39-2jhr-7qx8 Severity: high CVE: CVE-2026-65842
Plate: SSRF with response disclosure in DOCX image embedding
## Summary
`@platejs/docx-io` can fetch remote image URLs while converting HTML to DOCX. When an application converts attacker-controlled HTML in a server-side or privileged environment, this can cause the application environment to make unintended outbound requests and include fe
Indicators of compromise
- CVE-2026-65842cve
Original source: https://github.com/advisories/GHSA-4q39-2jhr-7qx8