40.3.1
3 years ago
2 days ago
Known vulnerabilities in the @udecode/plate-core package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
@udecode/plate-core is a The core of Plate – a plugin system for slate Affected versions of this package are vulnerable to Cross-site Scripting (XSS) through the Attack vectors for this exploit include convincing a user to open a malicious slate document on the vulnerable server, to open a document containing a malicious slate fragment, or to execute a slate operation on a collaborative document. Note: This behavior is only a vulnerability if the application's intention is to restrict the embedding of external content from arbitrary URLs. Otherwise it is behaving as expected. How to fix Cross-site Scripting (XSS)? Upgrade | <21.5.1>=22.0.0 <36.5.9>=37.0.0 <38.0.6 |