VDB
Sign up
LOW

GHSA-6ggm-pwr9-r5h2

XSS in @leanprover/unicode-input-component

Quick fix

GHSA-6ggm-pwr9-r5h2 — @leanprover/unicode-input-component: upgrade to the fixed version with the command below.

npm install @leanprover/unicode-input-component@0.2.0

Details

### Impact Projects that use [@leanprover/unicode-input-component](https://www.npmjs.com/package/@leanprover/unicode-input-component) are vulnerable to an XSS exploit in 0.1.9 of the package and lower. The component re-inserted text in the input element back into the input element as unescaped HTML.

### Patches The issue has been resolved in 0.2.0.

### Workarounds Replace the unicode input component with a basic HTML text field.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@leanprover/unicode-input-component
Introduced in: 0Fixed in: 0.2.0
Fixnpm install @leanprover/unicode-input-component@0.2.0

References