MEDIUM
GHSA-cg48-9hh2-x6mx
HTML Injection in preact
Quick fix
GHSA-cg48-9hh2-x6mx — preact: upgrade to the fixed version with the command below.
npm install preact@10.0.0-beta.1Details
Versions of `preact` 10.x on prerelease tags alpha and beta prior to 10.0.0-beta.1 are vulnerable to HTML Injection. Due to insufficient input validation the package allows attackers to inject JavaScript objects as virtual-dom nodes, which may lead to Cross-Site Scripting. This requires user input parsed with `JSON.parse()` to be passed directly into JSX without sanitization.
## Recommendation
Upgrade to version 10.0.0-beta.1.
Are you affected?
Enter the version of the package you're using.