취약점  ·  2026-08-21

Plate 리치 텍스트 에디터 (AI + shadcn/ui) — 공격자 제어 콘텐츠의 서버 측 HTML-대-DOCX 변환을 통한 SSRF

취약점Medium 영향도GlobalCVE-2026-65842
2026-08-20에 발표된 (CVSS 8.2, 높음), 이 SSRF 취약점은 Plate의 docx-io 변환 라이브러리에 의해 처
Plate markets itself explicitly as an AI-integrated editor; content passed through AI generation/completion features and then exported server-side to DOCX can carry attacker-influenced image URLs, making this a concrete AI-content-to-SSRF pipeline risk for document-generation features in AI writing assistants.
htmlToDocxBlob fetches remote image URLs embedded in attacker-controlled HTML during server-side or privileged DOCX conversion, allowing the converter to make requests to internal network resources and include the fetched response in the generated document.
@platejs/docx-io prior to Plate 53.3.2
Upgrade to Plate ≥53.3.2; restrict or allowlist outbound image-fetch destinations during server-side document conversion.
GitHub commit - udecode/plateNVD - CVE-2026-65842
라이브 피드에서 보기 AI 보안 및 거버넌스 관련 소식을 더 살펴보세요 — 매일 아침 업데이트.
피드 열기 →