CVE-2026-65842Disclosure

LOWCVSS 8.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Plate is a rich-text editor with AI and shadcn/ui. Prior to 53.3.2, @platejs/docx-io fetches remote image URLs while converting attacker-controlled HTML through htmlToDocxBlob in a server-side or privileged environment. The converter can make requests to internal network resources and include the fetched image bytes in the generated DOCX, allowing server-side request forgery with response disclosure. Applications can also incur resource consumption from attacker-selected remote responses. This issue is fixed in version 53.3.2.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-08-20); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-08-20: 2Mentions · 2026-09-03: 1Technical Details · 2026-08-20: 2Technical Details · 2026-09-03: 108-2009-03
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-202
Disclosure2
2026-09-031
Disclosure1
Full discourse3 posts
  • DailyCVE@dailycve
    Disclosure

    🔴 @platejs/docx-io (Plate), Server-Side Request Forgery (SSRF) with Response Disclosure, #CVE-2026-65842 (High) -DC-Sep2026-2133 https://dailycve.com/platejs-docx-io-plate-server-side-request-forgery-ssrf-with-response-disclosure-cve-2026-65842-high-dc-sep2026-2133/

    Post summary

    The tweet announces a newly disclosed SSRF vulnerability (CVE‑2026‑65842) in Plate with high severity and links to a dailycve article for more details, without mentioning PoCs, exploits, or active exploitation.

    0000031
    233 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-65842 Plate is a rich-text editor with AI and shadcn/ui. Prior to 53.3.2, @platejs/docx-io fetches remote image URLs while converting attacker-controlled HTML through htmlT… https://www.cve.org/CVERecord?id=CVE-2026-65842 ----- Traducción: CVE-2026-65842 Pla… https://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑65842, detailing a vulnerability in Plate’s @platejs/docx-io that fetches remote image URLs during HTML conversion in older versions, but it provides neither a PoC nor exploit, patch info, or evidence of active exploitation.

    0000026
    102 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-65842 Plate is a rich-text editor with AI and shadcn/ui. Prior to 53.3.2, @platejs/docx-io fetches remote image URLs while converting attacker-controlled HTML through htmlT… https://www.cve.org/CVERecord?id=CVE-2026-65842

    Post summary

    The post highlights CVE‑2026‑65842 affecting the Plate rich‑text editor, noting that prior to version 53.3.2 the library fetched remote image URLs from attacker‑controlled HTML.

    000001.7K
    58.0K followersView on X

Explore more