VDB
Sign up
HIGH7.3

GHSA-3qxh-p7jc-5xh6

Solid Lacks Escaping of HTML in JSX Fragments allows for Cross-Site Scripting (XSS)

Quick fix

GHSA-3qxh-p7jc-5xh6 — solid-js: upgrade to the fixed version with the command below.

npm install solid-js@1.9.4

Details

Inserts/JSX expressions inside illegal inlined JSX fragments lacked escaping, allowing user input to be rendered as HTML when put directly inside JSX fragments.

For instance, `?text=<svg/onload=alert(1)>` would trigger XSS here. ```js const [text] = createResource(() => { return new URL(getRequestEvent().request.url).searchParams.get("text"); });

return ( <> Text: {text()} </> ); ```

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/solid-js
Introduced in: 0Fixed in: 1.9.4
Fixnpm install solid-js@1.9.4

References