PT-2026-79065 · Unknown · @Platejs/Docx-Io
CVE-2026-65842
·
Published
2026-08-20
·
Updated
2026-09-03
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Plate versions prior to 53.3.2
Description
When converting attacker-controlled HTML through the
htmlToDocxBlob() function in a server-side or privileged environment, the @platejs/docx-io module fetches remote image URLs. This behavior allows for server-side request forgery (SSRF), where the converter can make requests to internal network resources and include the resulting image bytes in the generated DOCX file, leading to response disclosure. Additionally, applications may experience resource consumption caused by remote responses selected by an attacker.Recommendations
Update to version 53.3.2.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
@Platejs/Docx-Io