HIGH7.3
GHSA-3qxh-p7jc-5xh6
Solid Lacks Escaping of HTML in JSX Fragments allows for Cross-Site Scripting (XSS)
Quick fix
GHSA-3qxh-p7jc-5xh6 — solid-js: upgrade to the fixed version with the command below.
npm install solid-js@1.9.4Details
Inserts/JSX expressions inside illegal inlined JSX fragments lacked escaping, allowing user input to be rendered as HTML when put directly inside JSX fragments.
For instance, `?text=<svg/onload=alert(1)>` would trigger XSS here. ```js const [text] = createResource(() => { return new URL(getRequestEvent().request.url).searchParams.get("text"); });
return ( <> Text: {text()} </> ); ```
Are you affected?
Enter the version of the package you're using.