v53.3.2

jj-vcs/jjv53.3.2Jul 3, 2026by zbeyens

AI Summary

A patch release for the docx-io plugin that skips remote image URLs by default to improve security.

Key Highlights

  • Remote image URLs are now skipped by default during DOCX export
  • Migration guide provided for handling trusted remote images

New Features

  • Security enhancement for remote image handling

Full Release Notes

## `@platejs/docx-io`

### Patch Changes

- [#5053](https://github.com/udecode/plate/pull/5053) by [@zbeyens](https://github.com/zbeyens) – Skip remote image URLs by default during DOCX export.

  **Migration:** Convert trusted remote images to data URIs before calling `htmlToDocxBlob`, or pass `allowRemoteImages: true` only when the HTML source is trusted.

## Contributors

Thanks to everyone who contributed to this release:

@zbeyens

Full changelog: [`v53.3.1...v53.3.2`](https://github.com/udecode/plate/compare/v53.3.1...v53.3.2)