Threat Advisory

Plate SSRF Flaw Exposes Internal Resources via DOCX Image Embedding

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-65842 with a CVSS score of 8.2 is a high-severity vulnerability affecting @platejs/docx-io versions < 53.3.2 that allows SSRF with response disclosure in DOCX image embedding via the @platejs/docx-io package, which can fetch remote image URLs while converting HTML to DOCX, potentially causing unintended outbound requests and including fetched image data in the generated DOCX. This flaw affects applications using @platejs/docx-io to convert untrusted HTML that may contain remote image references, especially in server-side conversion workflows or environments with access to internal network resources. To exploit this vulnerability, an attacker must be able to provide malicious HTML input to a vulnerable application, which can then be used to make unintended outbound requests and include fetched image data in the generated DOCX. The business impact of this vulnerability is significant, as it allows an attacker to potentially gain unauthorized access to internal network resources.

RECOMMENDATION:

We recommend you to update @platejs/docx-io to version 53.3.2 or later.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-65842 with a CVSS score of 8.2 is a high-severity vulnerability affecting @platejs/docx-io versions < 53.3.2 that allows SSRF with response disclosure in DOCX image embedding via the @platejs/docx-io package, which can fetch remote image URLs while converting HTML to DOCX, potentially causing unintended outbound requests and including fetched image data in the generated DOCX. This flaw affects applications using @platejs/docx-io to convert untrusted HTML that may contain remote image references, especially in server-side conversion workflows or environments with access to internal network resources. To exploit this vulnerability, an attacker must be able to provide malicious HTML input to a vulnerable application, which can then be used to make unintended outbound requests and include fetched image data in the generated DOCX. The business impact of this vulnerability is significant, as it allows an attacker to potentially gain unauthorized access to internal network resources.

RECOMMENDATION:

We recommend you to update @platejs/docx-io to version 53.3.2 or later.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu