THREAT OPS › Threat News › [GHSA] GHSA-qrfj-mgw8-j9c6 (medium) — @platejs/core HTML deserialization can trigger browser behavior during parsing
[GHSA] GHSA-qrfj-mgw8-j9c6 (medium) — @platejs/core HTML deserialization can trigger browser behavior during parsing
GHSA-qrfj-mgw8-j9c6 Severity: medium CVE: CVE-2026-88976
@platejs/core HTML deserialization can trigger browser behavior during parsing
### Summary
HTML strings passed to Plate's core deserialization APIs were parsed in the active document. Certain HTML attributes could therefore trigger browser behavior during parsing, before the content was converted into editor nodes.
Applications that dese
Indicators of compromise
- CVE-2026-88976cve
Original source: https://github.com/advisories/GHSA-qrfj-mgw8-j9c6