VDB
Sign up
HIGH8.1

GHSA-4882-hxpr-hrvm

@udecode/plate-link does not sanitize URLs to prevent use of the `javascript:` scheme

Quick fix

GHSA-4882-hxpr-hrvm — @udecode/plate-link: upgrade to the fixed version with the command below.

npm install @udecode/plate-link@20.0.0

Details

### Impact Affected versions of the link plugin and link UI component do not sanitize URLs to prevent use of the `javascript:` scheme. As a result, links with JavaScript URLs can be inserted into the Plate editor through various means, including opening or pasting malicious content.

### Patches `@udecode/plate-link` 20.0.0 resolves this issue by introducing an `allowedSchemes` option to the link plugin, defaulting to `['http', 'https', 'mailto', 'tel']`. URLs using a scheme that isn't in this list will not be rendered to the DOM.

### Workarounds If you are unable to update `@udecode/plate-link` to version 20.0.0, we recommend overriding the `LinkElement` and `PlateFloatingLink` components with implementations that explicitly check the URL scheme before rendering any anchor elements.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@udecode/plate-link
Introduced in: 0Fixed in: 20.0.0
Fixnpm install @udecode/plate-link@20.0.0

References