LOW
GHSA-6ggm-pwr9-r5h2
XSS in @leanprover/unicode-input-component
Quick fix
GHSA-6ggm-pwr9-r5h2 — @leanprover/unicode-input-component: upgrade to the fixed version with the command below.
npm install @leanprover/unicode-input-component@0.2.0Details
### Impact Projects that use [@leanprover/unicode-input-component](https://www.npmjs.com/package/@leanprover/unicode-input-component) are vulnerable to an XSS exploit in 0.1.9 of the package and lower. The component re-inserted text in the input element back into the input element as unescaped HTML.
### Patches The issue has been resolved in 0.2.0.
### Workarounds Replace the unicode input component with a basic HTML text field.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/@leanprover/unicode-input-component
Introduced in:
0Fixed in: 0.2.0Fix
npm install @leanprover/unicode-input-component@0.2.0References
- https://github.com/leanprover/vscode-lean4/security/advisories/GHSA-6ggm-pwr9-r5h2[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-32732[ADVISORY]
- https://github.com/leanprover/vscode-lean4/pull/735[WEB]
- https://github.com/leanprover/vscode-lean4[PACKAGE]
- https://leanprover.zulipchat.com/#narrow/channel/113488-general/topic/weird.20behavior.20in.20loogle.20searchbar/near/578502003[WEB]