THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-qrfj-mgw8-j9c6 (medium) — @platejs/core HTML deserialization can trigger browser behavior during parsing

[GHSA] GHSA-qrfj-mgw8-j9c6 (medium) — @platejs/core HTML deserialization can trigger browser behavior during parsing

medgithub_advisoriesPublished 2026-09-17

GHSA-qrfj-mgw8-j9c6 Severity: medium CVE: CVE-2026-88976

@platejs/core HTML deserialization can trigger browser behavior during parsing

### Summary

HTML strings passed to Plate's core deserialization APIs were parsed in the active document. Certain HTML attributes could therefore trigger browser behavior during parsing, before the content was converted into editor nodes.

Applications that dese

Indicators of compromise

Original source: https://github.com/advisories/GHSA-qrfj-mgw8-j9c6